CVE-2026-7492: GitLab

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages.

Affected products

  • GitLab GitLab: from 9.1.0, before 18.11.7 (fixed in 18.11.7); from 19.0.0, before 19.0.4 (fixed in 19.0.4); from 19.1.0, before 19.1.2 (fixed in 19.1.2)

Published 2026-07-08. Last modified 2026-07-09.