
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6821 is an authorization bypass vulnerability in GitLab Enterprise Edition (EE) affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2. Under certain conditions, an authenticated user could bypass IP-based access restrictions and read limited merge request information from private projects due to missing authorization checks in a merge requests API endpoint. The vulnerability was disclosed on August 12, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-862 (Missing Authorization) — the merge requests API endpoint fails to enforce IP-based access restriction checks under certain conditions, allowing requests that should be blocked to proceed. An authenticated low-privileged user can send network requests to the affected API endpoint to retrieve merge request metadata from private projects they should not have access to. No user interaction is required, and attack complexity is low, making the flaw straightforward to exploit once an attacker has any valid authenticated session (GitHub Advisory, ENISA EUVD).
Successful exploitation allows an authenticated attacker to read limited merge request information from private GitLab EE projects that are protected by IP-based access restrictions, resulting in a confidentiality impact. There is no integrity or availability impact — the vulnerability is limited to unauthorized read access of merge request data. While the exposed data is described as "limited," it could include sensitive code review discussions, branch names, or development context that aids further reconnaissance (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (ENISA EUVD). The EPSS score is approximately 0.281%, placing it in the 21st percentile for exploitation likelihood within 30 days. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 334981) and Qualys (plugin 388347) (GitHub Advisory).
GET /api/v4/projects/:id/merge_requests) for a private project that the attacker's IP address should be restricted from accessing./api/v4/projects/:id/merge_requests originating from IP addresses outside the configured IP allowlist for a private project.GitLab has released patched versions: 19.0.6, 19.1.4, and 19.2.2. Organizations should upgrade to the appropriate patched release as the primary remediation (GitLab Patch Release). As a temporary measure, administrators should review and audit API access logs to identify any unauthorized access to merge request endpoints during the exposure window, and consider strengthening IP-based access control policies. Reviewing which users have authenticated access to the GitLab instance can also reduce the attack surface while patching is underway (ENISA EUVD).
Security monitoring platforms including SecurityOnline.info covered the GitLab patch release, and the vulnerability was catalogued by ENISA's EUVD and VulDB shortly after disclosure. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."