Database/Control plane, storage & DevOps
GitLab EE: guest-level user can read private security policy content they are not authorized to see
Impact
Improper authorization enforcement lets an authenticated user with only guest permissions read private security policy content under certain conditions. For a datacenter that runs GitLab as its CI/CD and GitOps source of truth, security policies describe what scanning, approval and enforcement rules apply to pipelines - useful reconnaissance for someone deciding which project's pipeline is least guarded before attempting to land code that runs on build or GPU runners. Confidentiality only; no write path or pipeline execution is claimed by the advisory.
Who can reach it
An authenticated GitLab user holding guest-level membership. No administrative access required; the instance must be GitLab EE on an affected version.
What to do
Upgrade to GitLab 19.2.7, 19.3.3, or 19.4.1 - all versions from 17.9 before those are affected. This is a standard GitLab patch-release upgrade and restart of the application services, no fleet-wide node work; self-managed operators should expect the usual brief GitLab maintenance window including migrations.
References
Related entries
- Grafana: alert rules API returns rules from folders the user cannot readCVE-2026-13719 · Grafana (alert rules API list endpoint, folder authorization)Medium
- GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobsCVE-2026-15387 · GitLab EE (Pipeline Execution Policy enforcement jobs, job dependency handling)Medium
- GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variablesCVE-2026-16794 · GitLab EE (compliance framework management authorization)Medium
- GitLab EE: authenticated user can view restricted group configuration settingsCVE-2026-18244 · GitLab EE (group settings page authorization)Medium
- GitLab EE: GraphQL query exposes policy configuration from an unauthorized namespaceCVE-2026-18433 · GitLab EE (GraphQL query for namespace policy configuration)Medium
- NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have noCVE-2026-22052 · NetApp ONTAP S3 NAS bucket directory listingMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.