CVE-2026-4523: GitLab

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.

Affected products

  • GitLab GitLab: from 15.11.0, before 19.2.7 (fixed in 19.2.7); from 19.3.0, before 19.3.3 (fixed in 19.3.3); version 19.4.0 only

Published 2026-09-29. Last modified 2026-10-05.