What is CVE-2026-4672?
GitLab has fixed an authorization issue in CE/EE that could allow an authenticated user with guest role permissions to access unauthorized test report contents under certain conditions. This affects versions from 18.4 prior to 19.0.5, 19.1 prior to 19.1.3, and 19.2 prior to 19.2.1. Users should apply the latest security patch immediately.
Azərbaycanca: GitLab CE/EE platformasında autentifikasiya olunmuş qonaq istifadəçilərə müəyyən şərtlər daxilində icazəsiz test hesabatlarının məzmununa giriş imkanı verən zəiflik aradan qaldırıldı. Bu problem 18.4-dən 19.0.5, 19.1.3 və 19.2.1 versiyalarına qədər təsir göstərir. İstifadəçilərə ən son təhlükəsizlik patch-ini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: GitLab
FAQ2
What permission level does an attacker need to exploit this vulnerability?
The vulnerability can only be exploited by an authenticated user with guest role permissions.
Which versions are affected by this issue?
The issue affects GitLab CE/EE versions from 18.4 prior to 19.0.5, 19.1 prior to 19.1.3, and 19.2 prior to 19.2.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.