CVE-2026-1338: Authorization Bypass Through User-Controlled Key in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to delete protected container registry tags due to improper authorization checks.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1338?
CVE-2026-1338 has a severity rating that indicates a significant security risk due to authorization bypass issues.
How do I fix CVE-2026-1338?
To fix CVE-2026-1338, update your GitLab CE/EE to version 18.9.7 or later, 18.10.6 or later, or 18.11.3 or later.
What versions of GitLab are affected by CVE-2026-1338?
CVE-2026-1338 affects GitLab CE/EE versions from 17.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3.
What type of vulnerability is CVE-2026-1338?
CVE-2026-1338 is classified as an authorization bypass vulnerability.
Who can be impacted by CVE-2026-1338?
Authenticated users with developer-role permissions may be impacted by CVE-2026-1338 as they could exploit it to delete protected resources.