Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196349 vulns · 36/41 feeds (7d)
← Back to list
4.3
CVE-2026-4879PATCHED
gitlab · gitlab

Missing Authorization in GitLab

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to view external status check configuration restricted to higher-privileged roles due to missing authorization on a merge request API endpoint.

Affected Products

VendorProductVersions
gitlabgitlab16.0, 19.1, 19.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegitlabcert_advisory90%

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/594839
  • https://hackerone.com/reports/3622861(technical-description, exploit, permissions-required)
  • https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/

Related News (3 articles)

Tier B
BSI Advisories10d ago
[NEU] [hoch] GitLab: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR11d ago
Multiples vulnérabilités dans GitLab (13 août 2026)
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-4879 | GitLab up to 19.0.5/19.1.3/19.2.1 Merge Request API Endpoint improper authorization
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
19.0.619.1.419.2.2
CWECWE-862
PublishedAug 12, 2026
Trending Score13
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 70
HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 33
HIGHCVE-2026-10053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 25
HIGHCVE-2026-15216
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13
HIGHCVE-2026-15217
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026
Patch Available
Aug 13, 2026