PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15077 GitLab CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-29T20:17:01.690Z and has not been modified since then. The NVD entry is currently Analyzed. This issue affects GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1, allowing authenticated users to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. GitLab EE administrators and users with access to AI-assisted code review functionality should verify project configurations and user access controls. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed to ensure proper mitigation and remediation.

Vendor
GitLab
Product
GitLab EE
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-29
Original CVE updated
2026-08-03
Advisory published
2026-07-29
Advisory updated
2026-08-03

Who should care

GitLab EE administrators and users with access to AI-assisted code review functionality should verify project configurations and user access controls. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed to ensure proper mitigation and remediation.

Technical summary

GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1 have an issue with AI-assisted code review functionality, allowing authenticated users to access information from unauthorized projects due to improper neutralization of untrusted content. This issue may allow authenticated users to access unauthorized project information. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Official records indicate improper neutralization of untrusted content. Verify project configurations and user access controls, and review compensating controls for exposed systems while remediation is scheduled and verified.

Defensive priority

Authenticated users may access unauthorized project information. Verify project configurations and user access controls.

Recommended defensive actions

  • Verify and update GitLab EE to version 19.1.3 or later
  • Verify and update GitLab EE to version 19.2.1 or later
  • Review project configurations and user access controls
  • Monitor AI-assisted code review functionality for suspicious activity
  • Verify project configurations and user access controls for exposure
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1 have an issue with AI-assisted code review functionality. Official records indicate improper neutralization of untrusted content. The CVE record was published on 2026-07-29T20:17:01.690Z and has not been modified since then. The NVD entry is currently Analyzed. Verify project configurations and user access controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15077 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15077

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15077 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15077

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.