CVE-2026-7492: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.11.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7492?
CVE-2026-7492 has a medium severity rating of 5.3.
How do I fix CVE-2026-7492?
To fix CVE-2026-7492, update to GitLab version 18.11.7 or later, 19.0.4 or later, or 19.1.2 or later.
What systems are affected by CVE-2026-7492?
CVE-2026-7492 affects all versions of GitLab CE/EE from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2.
What type of vulnerability is described in CVE-2026-7492?
CVE-2026-7492 is a missing authorization vulnerability that could allow an unauthenticated user to determine the existence of a private project.
When was CVE-2026-7492 published?
CVE-2026-7492 was published on July 8, 2026.