What is CVE-2026-19228?
CVE-2026-19228 is a vulnerability in GitLab EE affecting versions 19.1 before 19.1.4 and 19.2 before 19.2.2. Under certain conditions, it could allow an authenticated user to cause AI usage to be attributed to another namespace due to improper authorization. Organizations using affected versions should apply the security updates immediately.
Azərbaycanca: CVE-2026-19228, GitLab EE-nin 19.1-19.1.4 və 19.2-19.2.2 versiyalarını təsir edən bir boşluqdur. Müəyyən şərtlər altında autentifikasiya olunmuş istifadəçinin AI istifadəsini başqa namespace-ə aid etməsinə imkan verə bilərdi. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal təhlükəsizlik yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: GitLab
FAQ2
Which GitLab versions are affected by CVE-2026-19228?
This vulnerability affects GitLab EE versions 19.1 before 19.1.4 and 19.2 before 19.2.2.
What can an authenticated user do by exploiting CVE-2026-19228?
An authenticated user can cause AI usage to be attributed to another namespace due to improper authorization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.