CVE-2026-11379 PUBLISHED

Incorrect Authorization in GitLab

Assigner: GitLab
Reserved: 05.06.2026 Published: 25.06.2026 Updated: 25.06.2026

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor GitLab
Product GitLab
Versions Default: unaffected
  • affected from 13.11 to 18.11.6 (excl.)
  • affected from 19.0 to 19.0.3 (excl.)
  • affected from 19.1 to 19.1.1 (excl.)

Solutions

Upgrade to versions 18.11.6, 19.0.3, 19.1.1 or above.

Credits

  • This vulnerability has been discovered internally by GitLab team member David Nelson finder

References

Problem Types

  • CWE-863: Incorrect Authorization CWE