PT-2026-56616 · Gitlab · Gitlab Ce/Ee

CVE-2026-7492

·

Published

2026-07-08

·

Updated

2026-07-13

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 9.1 through 18.11.6 GitLab CE/EE versions 19.0 through 19.0.3 GitLab CE/EE versions 19.1 through 19.1.1
Description Improper authorization controls on cross-project reference pages could allow an unauthenticated user to determine if a private project exists.
Recommendations Update GitLab CE/EE to version 18.11.7 or later. Update GitLab CE/EE to version 19.0.4 or later. Update GitLab CE/EE to version 19.1.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09847
BIT-GITLAB-2026-7492
CVE-2026-7492

Affected Products

Gitlab Ce/Ee