Unrated severityNVD Advisory· Published Dec 17, 2023· Updated Apr 23, 2026
Improper User Management in GitLab
CVE-2023-3907
Description
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
Affected products
3- Range: >=16.0, <16.4.4 || >=16.5, <16.5.4 || >=16.6, <16.6.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/2058934mitretechnical-descriptionexploitpermissions-required
- gitlab.com/gitlab-org/gitlab/-/issues/418878mitreissue-trackingpermissions-required
News mentions
1- GitLab Security Release: 16.6.2, 16.5.4, 16.4.4GitLab Security Releases · Dec 13, 2023