What is CVE-2026-16494?
GitLab EE versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 contained a vulnerability where missing authorization checks could allow an authenticated user to modify project settings restricted to higher-privileged roles. Organizations using affected versions should immediately upgrade to 19.1.4 or 19.2.2.
Azərbaycanca: GitLab EE-nin 19.1.4-dən əvvəlki 19.1 versiyalarında və 19.2.2-dən əvvəlki 19.2 versiyalarında müəyyən şərtlər altında autentifikasiya olunmuş istifadəçiyə çatışmayan avtorizasiya yoxlamaları səbəbindən daha yüksək səlahiyyətli rollara məxsus layihə parametrlərini dəyişməyə imkan verən boşluq aradan qaldırılıb. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal 19.1.4 və ya 19.2.2 versiyalarına yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: GitLab
FAQ2
Which versions of GitLab EE are affected by the CVE-2026-16494 vulnerability?
This vulnerability affects GitLab EE versions from 19.1 before 19.1.4 and 19.2 before 19.2.2.
How can organizations protect against CVE-2026-16494?
Affected organizations should immediately upgrade GitLab EE to version 19.1.4 or 19.2.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.