PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-4916 GitLab CVE debrief

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations. This issue has a CVSS score of 2.7 and LOW severity. The vulnerability involves improper authorization checks on member management operations in GitLab CE/EE.

Vendor
GitLab
Product
GitLab CE/EE
CVSS
LOW 2.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Administrators and users of GitLab CE/EE versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 should apply patches or mitigations to prevent potential unauthorized group member modifications. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.

Technical summary

The vulnerability, with a CVSS score of 2.7 and LOW severity, involves improper authorization checks on member management operations in GitLab CE/EE. This could allow authenticated users with custom role permissions to demote or remove higher-privileged group members. The issue affects versions 18.2 through 18.8.9, 18.9 through 18.9.5, and 18.10 through 18.10.3 of GitLab CE/EE. Affected administrators and users should apply patches or mitigations to prevent potential unauthorized group member modifications.

Defensive priority

Low priority, but immediate action recommended for affected GitLab CE/EE instances to prevent potential exploitation. Review compensating controls for exposed systems while remediation is scheduled and verified.

Recommended defensive actions

  • Apply patches or updates to affected GitLab CE/EE versions
  • Review and adjust custom role permissions for authenticated users
  • Monitor group member management operations for suspicious activity
  • Implement compensating controls to detect and prevent unauthorized modifications
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-08T23:17:00.053Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The vulnerability affects GitLab CE/EE versions 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3. Evidence limits suggest that an authenticated user with custom role permissions could potentially demote or remove higher-privileged group members due to improper authorization checks.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T23:17:00.053Z and has not been modified since then. The NVD entry is currently Analyzed.