GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: guest-level user can read private security policy content they are not authorized to see

CVSS 4.3CVE-2026-10518Control plane, storage & DevOpscurated

Impact

Improper authorization enforcement lets an authenticated user with only guest permissions read private security policy content under certain conditions. For a datacenter that runs GitLab as its CI/CD and GitOps source of truth, security policies describe what scanning, approval and enforcement rules apply to pipelines - useful reconnaissance for someone deciding which project's pipeline is least guarded before attempting to land code that runs on build or GPU runners. Confidentiality only; no write path or pipeline execution is claimed by the advisory.

Who can reach it

An authenticated GitLab user holding guest-level membership. No administrative access required; the instance must be GitLab EE on an affected version.

What to do

Upgrade to GitLab 19.2.7, 19.3.3, or 19.4.1 - all versions from 17.9 before those are affected. This is a standard GitLab patch-release upgrade and restart of the application services, no fleet-wide node work; self-managed operators should expect the usual brief GitLab maintenance window including migrations.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.