securityonline.info 7/30/2026, 4:30:49 AM · external

GitLab patches critical flaw CVE-2026-6267 allowing data access

GitLab patches critical flaw CVE-2026-6267 allowing data access
CyberSIXT Evidence Panel
Primary Source docs.gitlab.com
CISA KEV Not in KEV
Patch Patch Available

GITLAB has released version 19.2.1, addressing 13 security vulnerabilities. The most critical is CVE-2026-6267, rated 8.5 for high severity, which allows unauthorized data access. No confirmed exploitation has been reported. Other notable vulnerabilities include CVE-2026-12436 (8.4) and CVE-2026-15975 (7.5). Users are advised to upgrade immediately to mitigate risks, as many issues can be exploited by low-privilege accounts.

The vulnerabilities were primarily identified via GitLab's HackerOne bug bounty program, indicating strong scrutiny of the platform. Existing affected versions include those prior to the latest release.

View Primary Source Via securityonline.info

Article by CyberSIXT