CVE-2026-19228 PUBLISHED

Authorization Bypass Through User-Controlled Key in GitLab

Assigner: GitLab
Reserved: 07.08.2026 Published: 12.08.2026 Updated: 13.08.2026

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
CVSS Score: 8.5

Product Status

Vendor GitLab
Product GitLab
Versions Default: unaffected
  • affected from 19.1 to 19.1.4 (excl.)
  • affected from 19.2 to 19.2.2 (excl.)

Solutions

Upgrade to versions 19.1.4, 19.2.2 or above.

Credits

  • This vulnerability has been discovered internally by GitLab team member Dennis Appelt finder

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE