Medium severity4.9NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-11827
CVE-2026-11827
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=9.5.0,<18.11.7
- (no CPE)range: from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2
- Range: from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2
Patches
Vulnerability mechanics
References
2- docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/nvdVendor Advisory
- hackerone.com/reports/3720483nvdPermissions Required
News mentions
2- GitLab Patches Eight Security Vulnerabilities Across Community and Enterprise EditionsCyber Security News · Jul 9, 2026
- GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7GitLab Security Releases · Jul 8, 2026