CVE-2026-4916
נמוכה 2.7
תיאור (מקור, אנגלית)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom role permissions to demote or remove higher-privileged group members due to improper authorization checks on member management operations.
מדדים
- CVSS 3.1
-
2.7 (LOW)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-28/7/2026
- CWE
- CWE-862
מוצרים מושפעים
gitlab: gitlab
קישורים
- https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-rele… Release NotesVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/565414 Broken Link
- https://hackerone.com/reports/3301240 Permissions Required