Intel

AIKIDO-2026-672683

gitlab-ce is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-7514 Published 3 days ago

43

Medium Risk

This Affects:

OSgitlab-ce
13.9.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

The Generic Package Registry does not enforce adequate authorization on package file operations. An authenticated Developer can substitute package file content and hide packages from their owners. The fix authorizes Generic Package Registry mutations so Developers cannot replace or conceal others' packages.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use the Generic Package Registry.

Background info

gitlab-ce is vulnerable to Missing Authorization in versions 13.9.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform