CVE-2026-4398

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-08 23:16

Updated : 2026-08-28 16:18


NVD link : CVE-2026-4398

Mitre link : CVE-2026-4398

CVE.ORG link : CVE-2026-4398


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key