What is CVE-2026-18433?
CVE-2026-18433 is an authorization flaw in GitLab EE affecting versions before 19.1.4 and 19.2 before 19.2.2, allowing an authenticated user to read policy configurations of unauthorized namespaces. Users should immediately upgrade to versions 19.1.4, 19.2.2, or later.
Azərbaycanca: CVE-2026-18433 GitLab EE-nin 19.1.4-dən əvvəlki və 19.2.2-dən əvvəlki versiyalarını təsir edən səlahiyyət yoxlaması zəifliyidir. Bu boşluq autentifikasiya olunmuş istifadəçiyə aid olmadığı namespace-in siyasət konfiqurasiyasını oxumağa imkan verir. İstifadəçilərə təcili olaraq 19.1.4 və ya 19.2.2 və daha yuxarı versiyalara yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: GitLab
FAQ2
Which GitLab versions are affected by CVE-2026-18433?
CVE-2026-18433 affects all GitLab EE versions prior to 19.1.4 and versions 19.2 prior to 19.2.2.
What is the impact of CVE-2026-18433?
This flaw allows an authenticated user to read the policy configurations of namespaces they are not authorized to access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.