SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-7492

MEDIUM · CVSS 4.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

GitLab versions prior to 18.11.7, 19.0.4, and 19.1.2 are vulnerable due to improper authorization controls that may allow unauthenticated users to discover the existence of private projects through cross-project reference pages. This could lead to unintended exposure of sensitive project information. Organizations using affected versions should prioritize updating their GitLab installations to mitigate this risk.

CVE
CVE-2026-7492
Severity
MEDIUM
CVSS
4.3
EPSS
0.25%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

Related CVEs

Other vulnerabilities affecting the same vendor(s)