Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the Generic Package Registry. | |
| Title | Missing Authorization in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-09-16T15:45:18.169Z
Reserved: 2026-04-30T15:33:45.538Z
Link: CVE-2026-7514
Updated: 2026-09-16T15:45:14.397Z
Status : Received
Published: 2026-09-16T07:16:37.560
Modified: 2026-09-16T16:17:18.557
Link: CVE-2026-7514
No data.
OpenCVE Enrichment
Updated: 2026-09-16T15:30:11Z