Medium severity4.3NVD Advisory· Published Jul 29, 2026· Updated Aug 3, 2026
CVE-2026-15077
CVE-2026-15077
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <19.1.3, <19.2.1
<19.1.3, <19.2.1+ 2 more
- (no CPE)range: <19.1.3, <19.2.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=19.1.0,<19.1.3
- cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*
Patches
Vulnerability mechanics
References
1- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-released/nvdRelease NotesVendor Advisory
News mentions
2- GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash ServersCyber Security News · Jul 30, 2026
- GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5GitLab Security Releases · Jul 29, 2026