PatchSiren cyber security CVE debrief
CVE-2026-4916 GitLab CVE debrief
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations. This issue has a CVSS score of 2.7 and LOW severity. The vulnerability involves improper authorization checks on member management operations in GitLab CE/EE.
- Vendor
- GitLab
- Product
- GitLab CE/EE
- CVSS
- LOW 2.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of GitLab CE/EE versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 should apply patches or mitigations to prevent potential unauthorized group member modifications. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed.
Technical summary
The vulnerability, with a CVSS score of 2.7 and LOW severity, involves improper authorization checks on member management operations in GitLab CE/EE. This could allow authenticated users with custom role permissions to demote or remove higher-privileged group members. The issue affects versions 18.2 through 18.8.9, 18.9 through 18.9.5, and 18.10 through 18.10.3 of GitLab CE/EE. Affected administrators and users should apply patches or mitigations to prevent potential unauthorized group member modifications.
Defensive priority
Low priority, but immediate action recommended for affected GitLab CE/EE instances to prevent potential exploitation. Review compensating controls for exposed systems while remediation is scheduled and verified.
Recommended defensive actions
- Apply patches or updates to affected GitLab CE/EE versions
- Review and adjust custom role permissions for authenticated users
- Monitor group member management operations for suspicious activity
- Implement compensating controls to detect and prevent unauthorized modifications
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-04-08T23:17:00.053Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. The vulnerability affects GitLab CE/EE versions 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3. Evidence limits suggest that an authenticated user with custom role permissions could potentially demote or remove higher-privileged group members due to improper authorization checks.
Official resources
-
CVE-2026-4916 CVE record
CVE.org
-
CVE-2026-4916 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Release Notes, Vendor Advisory
-
Source reference
[email protected] - Broken Link
-
Source reference
[email protected] - Permissions Required
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T23:17:00.053Z and has not been modified since then. The NVD entry is currently Analyzed.