Gitlab · Gitlab Ce/Ee · CVE-2026-5796
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 13.6 through 18.11.5
GitLab CE/EE versions 19.0 through 19.0.2
GitLab CE/EE versions 19.1 through 19.1.0
**Description**
Incorrect authorization checks in the group packages feature allow an authenticated user with Reporter-level group permissions to view package metadata from projects where the Package Registry is disabled.
**Recommendations**
Update to version 18.11.6
Update to version 19.0.3
Update to version 19.1.1