CVE-2026-4523

Summary

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.

Affected Software

VendorProductVersion RangeStatus
GitLabGitLab15.11 < 19.2.7affected
GitLabGitLab19.3 < 19.3.3affected
GitLabGitLab19.4 < 19.4.1affected

Weaknesses

  • CWE-862: CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References