Skip to content
Multiple Vulnerabilities Remediated in GitLab Affecting Various Versions

Multiple Vulnerabilities Remediated in GitLab Affecting Various Versions

First seen 26 Mar 2026, 20:19 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 27, 2026 at 20:17 UTC
  • •GitLab has patched multiple vulnerabilities affecting versions 11.10 to 18.10.1.
  • •CVE-2026-2726 and CVE-2026-4363 involve unauthorized access due to access control issues.
  • •CVE-2025-13436 could lead to denial of service through resource exhaustion.

GitLab has addressed several vulnerabilities across its CE and EE versions, impacting users from versions 11.10 to 18.10.1. CVE-2026-2726 allows authenticated users to perform unauthorized actions on merge requests due to improper access control. CVE-2026-4363 could enable unauthorized resource access due to improper caching of authorization decisions. CVE-2025-13436 permits denial of service through excessive resource consumption related to CI inputs. CVE-2026-1724 exposes API tokens of self-hosted AI models to unauthenticated users due to access control flaws. All vulnerabilities were published on March 25, 2026, and patches are now available. Users are urged to update their systems to mitigate these risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 196d ago How this analysis works

Timeline

2026-03-25
CVE-2026-1724 published
2026-03-25
CVE-2026-2726 published
2026-03-25
CVE-2025-13436 published
2026-03-25
CVE-2026-4363 published
2026-03-26
GitLab releases patches for all vulnerabilities

More articles in this cluster (4)

Following this threat?

Track CVE-2025-13436 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed