CVE-2026-4523

EUVD-2026-88690
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitLabCNA
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.54%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
gitlabgitlab
15.11 ≤
𝑥
< 19.2.7
CNA
gitlabgitlab
19.3 ≤
𝑥
< 19.3.3
CNA
gitlabgitlab
19.4 ≤
𝑥
< 19.4.1
CNA