Medium severity5.3NVD Advisory· Published Sep 15, 2026
CVE-2026-82837
CVE-2026-82837
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.
Affected products
1- Range: from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
Patches
Vulnerability mechanics
References
1News mentions
1- GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8GitLab Security Releases · Sep 10, 2026