Gitlab · Gitlab · CVE-2026-7514
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 13.9 through 19.1.7
GitLab CE/EE versions 19.2 through 19.2.5
GitLab CE/EE versions 19.3 through 19.3.1
**Description**
An authenticated user with developer-role permissions can substitute package file content and hide packages from their owners. This is caused by improper authorization checks within the Generic Package Registry.
**Recommendations**
Update to version 19.1.8
Update to version 19.2.6
Update to version 19.3.2