Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2005 articles · 105796 vulns · 36/41 feeds (7d)
← Back to list
6.8
CVE-2026-1724
gitlab · gitlab

Missing Authentication for Critical Function in GitLab

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.

Affected Products

VendorProductVersions
gitlabgitlab18.5, 18.9, 18.10

References

  • https://hackerone.com/reports/3531412(technical-description, exploit, permissions-required)
  • https://gitlab.com/gitlab-org/gitlab/-/work_items/588334
  • https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/

Related News (1 articles)

Tier B
CERT-FR5d ago
Multiples vulnérabilités dans GitLab (25 mars 2026)
→ No new info (linked only)
CVSS 3.16.8 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-306
Published3/25/2026
Last enriched3d ago
Trending Score11
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-2370EXP
Improper Handling of Parameters in GitLab
Trending: 58
HIGHCVE-2026-2995
GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addr
Trending: 23
HIGHCVE-2026-3988
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a d
Trending: 23
MEDIUMCVE-2026-2726
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform un
Trending: 11
MEDIUMCVE-2026-2973
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arb
Trending: 11

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 25, 2026
Discovered by ZDM
Mar 26, 2026