High severity8.5NVD Advisory· Published Aug 12, 2026· Updated Aug 19, 2026
CVE-2026-19228
CVE-2026-19228
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 19.1 <= versions < 19.1.4, 19.2 <= versions < 19.2.2
Patches
Vulnerability mechanics
References
1News mentions
2- GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization FlawsCyber Security News · Aug 13, 2026
- GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6GitLab Security Releases · Aug 12, 2026