Gitlab · Gitlab Ce/Ee · CVE-2026-11379
**Name of the Vulnerable Software and Affected Versions**
GitLab EE versions 13.11 through 18.11.5
GitLab EE versions 19.0 through 19.0.2
GitLab EE versions 19.1
**Description**
Incorrect authorization in DAST (Dynamic Application Security Testing) site profile management allows a user with the Developer role to exfiltrate DAST site profile secrets under certain conditions.
**Recommendations**
Update GitLab EE versions 13.11 through 18.11.5 to 18.11.6.
Update GitLab EE versions 19.0 through 19.0.2 to 19.0.3.
Update GitLab EE version 19.1 to 19.1.1.