Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2005 articles · 105796 vulns · 36/41 feeds (7d)
← Back to list
4.3
CVE-2026-2726PATCHED
gitlab · gitlab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform un

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to perform unauthorized actions on merge requests in other projects due to improper access control during cross-repository operations.

Affected Products

VendorProductVersions
gitlabgitlab< 18.8.7, < 18.8.7, < 18.9.3, < 18.9.3

References

  • https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/(Release Notes, Vendor Advisory)
  • https://gitlab.com/gitlab-org/gitlab/-/work_items/590717(Broken Link)
  • https://hackerone.com/reports/3543886(Permissions Required, Exploit)

Related News (1 articles)

Tier B
CERT-FR5d ago
Multiples vulnérabilités dans GitLab (25 mars 2026)
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available18.8.7, 18.9.3
CWECWE-863
Published3/25/2026
Last enriched3d ago
Trending Score11
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-2370EXP
Improper Handling of Parameters in GitLab
Trending: 58
HIGHCVE-2026-2995
GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addr
Trending: 23
HIGHCVE-2026-3988
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a d
Trending: 23
MEDIUMCVE-2026-1724
Missing Authentication for Critical Function in GitLab
Trending: 11
MEDIUMCVE-2026-2973
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arb
Trending: 11

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 25, 2026
Patch Available
Mar 26, 2026
Discovered by ZDM
Mar 26, 2026