PoC Index

CVE-2026-11827

MEDIUM 4.9EPSS 0.4%

GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls.

CVSS v3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
0.44% chance of exploitation in the next 30 days, 37th percentile
Published
2026-07-08
Updated
2026-07-09

Proof-of-concept exploits (1)

References

Related