CVE-2026-4523: GitLab
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
Affected products
- GitLab GitLab: from 15.11.0, before 19.2.7 (fixed in 19.2.7); from 19.3.0, before 19.3.3 (fixed in 19.3.3); version 19.4.0 only
Published 2026-09-29. Last modified 2026-10-05.