CVE-2026-19228
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-19228 is an authorization bypass vulnerability in GitLab Enterprise Edition (EE) that allows an authenticated user to cause AI usage to be attributed to another namespace by supplying manipulated identity information in requests. It affects GitLab EE versions 19.1.0 through 19.1.3 and 19.2.0 through 19.2.1. The vulnerability was published on August 12, 2026, and patches were released the same day. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory).

Technical details

The root cause is improper authorization of identity information supplied in API requests, classified as CWE-639 (Authorization Bypass Through User-Controlled Key). Under certain conditions, GitLab EE fails to validate that the namespace identity included in a request matches the authenticated user's actual namespace, allowing the attacker to substitute another namespace's identifier. This is a network-exploitable, low-complexity attack requiring only low-level authenticated access with no user interaction, and the scope change indicates impact extends beyond the attacker's own namespace (GitHub Advisory). No public proof-of-concept code has been identified.

Impact

Successful exploitation allows an authenticated attacker to falsely attribute AI feature usage and associated costs to a victim namespace they do not control, resulting in high integrity impact against that namespace. Additionally, the misdirected AI usage could disrupt AI service availability for the targeted namespace (low availability impact). There is no confidentiality impact, as the vulnerability does not expose data from other namespaces (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of publication. The NVD SSVC assessment classifies exploitation as "none" and the attack as not automatable. The EPSS score is approximately 0.23%, placing it in the 14th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: upgrade GitLab EE to version 19.1.4 or later (for 19.1.x users), or to version 19.2.2 or later (for 19.2.x users). No configuration-based workaround has been published; upgrading is the recommended remediation. Organizations should also implement request validation controls to ensure identity information in AI-related requests is verified against the authenticated user's namespace (GitHub Advisory, GitLab Patch Release).

Community reactions

Security news outlets including CyberSecurityNews and SecurityOnline.info covered the GitLab 19.2.2 patch release, noting it addressed 13 security flaws including this vulnerability. Coverage was routine and did not indicate elevated concern from the security community, consistent with the absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19478CRITICAL9.4
  • GitLab logoGitLab
  • gitlab-rails-19.1
NoYesAug 17, 2026
CVE-2026-19228HIGH8.5
  • GitLab logoGitLab
  • gitlab
NoYesAug 12, 2026
CVE-2026-19650HIGH7.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 17, 2026
CVE-2026-6821MEDIUM4.3
  • GitLab logoGitLab
  • gitlab
NoYesAug 12, 2026
CVE-2026-4879MEDIUM4.3
  • GitLab logoGitLab
  • gitlab
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management