CVE-2026-82837
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions could have allowed an authenticated user to access sensitive credentials and tokens without transiting the expected proxy due to improper authorization checks on internal data emission endpoints.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.40%
- CWE
- CWE-201
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-24477 — AnythingLLM has key leak in `systemSettings.js`
- CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
- CVE-2026-27934 — Discourse leaks private topic title and post excerpt via user action API endpoint
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2020-37093 — Netis E1+ 1.2.32533 - Unauthenticated WiFi Password Leak
- CVE-2026-27516 — Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure
- CVE-2025-66566 — yawkat LZ4 Java has a possible information leak in Java safe decompressor
- CVE-2026-8924 — trailing dot domain super cookie