PatchSiren cyber security CVE debrief
CVE-2026-2619 GitLab CVE debrief
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. This issue has a CVSS score of 4.3, indicating a medium severity. The vulnerability allows an authenticated user with auditor privileges to modify vulnerability flag data in private projects. Users of GitLab EE versions 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 should review and apply the provided patches to prevent potential modification of vulnerability flag data in private projects by authenticated users with auditor privileges.
- Vendor
- GitLab
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-20
Who should care
Users of GitLab EE versions 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 should review and apply the provided patches to prevent potential modification of vulnerability flag data in private projects by authenticated users with auditor privileges. This includes operators, platform administrators, vulnerability management teams, and security teams who need to ensure the security and integrity of their projects.
Technical summary
The issue in GitLab EE could allow an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. This affects versions 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3. The CVSS score for this vulnerability is 4.3, indicating a medium severity. The vulnerability is caused by incorrect authorization checks in GitLab EE. An authenticated user with auditor privileges can modify vulnerability flag data in private projects, which could lead to unauthorized changes.
Defensive priority
Medium priority should be given to patching GitLab EE versions 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 to prevent potential exploitation of this vulnerability. Additionally, review and update access controls for auditor privileges in private projects, and monitor for any unauthorized modifications to vulnerability flag data.
Recommended defensive actions
- Apply patches to GitLab EE versions 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3
- Review and update access controls for auditor privileges in private projects
- Monitor for any unauthorized modifications to vulnerability flag data
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-04-08T23:16:58.557Z and was last modified on 2026-07-20T20:10:00.110Z. The NVD entry is currently Analyzed. This issue affects GitLab EE versions 18.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3. The vulnerability allows an authenticated user with auditor privileges to modify vulnerability flag data in private projects due to incorrect authorization. The CVSS score for this vulnerability is 4.3, indicating a medium severity. Users should review and apply patches to prevent potential exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-2619 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-2619
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-2619 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2619
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://gitlab.com/gitlab-org/gitlab/-/work_items/590430
[email protected] - Broken Link
-
Source reference
Unverified legacy reference
URL: https://hackerone.com/reports/3554982
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.