#VU124609 Improper Authentication in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-4363
Published: March 25, 2026 / Updated: March 26, 2026
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote user to gain unauthorized access to resources.
The vulnerability exists due to improper caching of authorization decisions in authorization caching when handling requests under certain conditions. A remote user can send a specially crafted request to exploit stale or incorrect authorization cache entries and gain unauthorized access to resources.