GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: developer-role user can read external status check configuration for a merge request

CVE-2026-4879Control plane, storage & DevOpscurated

Impact

A merge request API endpoint is missing an authorization check, so a developer-role account can read external status check configuration that is meant for higher-privileged roles. External status checks are how a self-managed GitLab defers merge approval to an outside system, so the configuration names the endpoints and gates standing between a change and the pipelines that build fleet images. The exposure is read-only and GitLab scores confidentiality low; nothing in the record describes altering or bypassing a status check. Affects 16.0 before 19.0.6, 19.1 before 19.1.4 and 19.2 before 19.2.2.

Who can reach it

An authenticated GitLab user with developer-role permissions on the project, over the instance API. No maintainer or owner role is required.

What to do

Upgrade to 19.0.6, 19.1.4 or 19.2.2 per the GitLab 19.2.2 patch release - a package upgrade and service restart (Omnibus reconfigure/restart or a Helm chart bump), no node drain. If the disclosed status check endpoints carry their own secrets, rotate them.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.