← Back

CVE-2026-11379

nvd nist
Published: Jun 25, 2026Modified: Jun 26, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 3.6
Source: cve@gitlab.com (Secondary)

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions.

Affected (3)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 13.11.0 to 18.11.6
From 19.0.0 to 19.0.3
Version 19.1.0

References (2)

Timeline

No history available yet.