
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19228 is an authorization bypass vulnerability in GitLab Enterprise Edition (EE) that allows an authenticated user to cause AI usage to be attributed to another namespace by supplying manipulated identity information in requests. It affects GitLab EE versions 19.1.0 through 19.1.3 and 19.2.0 through 19.2.1. The vulnerability was published on August 12, 2026, and patches were released the same day. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory).
The root cause is improper authorization of identity information supplied in API requests, classified as CWE-639 (Authorization Bypass Through User-Controlled Key). Under certain conditions, GitLab EE fails to validate that the namespace identity included in a request matches the authenticated user's actual namespace, allowing the attacker to substitute another namespace's identifier. This is a network-exploitable, low-complexity attack requiring only low-level authenticated access with no user interaction, and the scope change indicates impact extends beyond the attacker's own namespace (GitHub Advisory). No public proof-of-concept code has been identified.
Successful exploitation allows an authenticated attacker to falsely attribute AI feature usage and associated costs to a victim namespace they do not control, resulting in high integrity impact against that namespace. Additionally, the misdirected AI usage could disrupt AI service availability for the targeted namespace (low availability impact). There is no confidentiality impact, as the vulnerability does not expose data from other namespaces (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of publication. The NVD SSVC assessment classifies exploitation as "none" and the attack as not automatable. The EPSS score is approximately 0.23%, placing it in the 14th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
GitLab has released patched versions addressing this vulnerability: upgrade GitLab EE to version 19.1.4 or later (for 19.1.x users), or to version 19.2.2 or later (for 19.2.x users). No configuration-based workaround has been published; upgrading is the recommended remediation. Organizations should also implement request validation controls to ensure identity information in AI-related requests is verified against the authenticated user's namespace (GitHub Advisory, GitLab Patch Release).
Security news outlets including CyberSecurityNews and SecurityOnline.info covered the GitLab 19.2.2 patch release, noting it addressed 13 security flaws including this vulnerability. Coverage was routine and did not indicate elevated concern from the security community, consistent with the absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."