SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15077

MEDIUM · CVSS 4.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

GitLab versions prior to 19.1.3 and 19.2.1 are vulnerable to an issue that may allow authenticated users to access unauthorized project information through the AI-assisted code review feature due to improper handling of untrusted content. This could lead to information disclosure, impacting the confidentiality of project data. Organizations using affected versions should prioritize updating to the latest releases to mitigate this risk.

CVE
CVE-2026-15077
Severity
MEDIUM
CVSS
4.3
EPSS
0.25%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.

Related CVEs

Other vulnerabilities affecting the same vendor(s)