Sceawere

Vulnerability Detail

CVE-2026-19228UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GitLab Namespace Identity Authorization Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
2h ago
Vendor
GitLab
Product
GitLab
Attack Type
CWE-639: Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-12T20:17:42.213Z",
  "pubdate": "2026-08-12T20:17:42.213Z",
  "executiveSummary": "An improper authorization vulnerability has been identified in GitLab EE that permits an authenticated user to manipulate identity information within requests, resulting in the attribution of AI usage to an unintended namespace.\nThe flaw impacts GitLab EE versions starting from 19.1 prior to 19.1.4 and versions starting from 19.2 prior to 19.2.2.\nThe primary impact involves resource misattribution, specifically concerning AI consumption metrics and billing or quota allocations tied to affected namespaces.\nExploitation requires an authenticated user with the capability to submit crafted requests where identity parameters can be supplied or overridden without proper server-side validation against the session context.\nRisk implications include resource exhaustion of target namespaces, metric tampering, and potential quota denial of service for legitimate namespace owners.\nOrganizations utilizing the affected GitLab EE versions must apply the vendor-provided security patches immediately to enforce rigorous authorization checks on identity metadata.",
  "technicalDetails": "The vulnerability stems from improper authorization of identity information supplied in client requests processed by GitLab EE AI subsystems.\nThe root cause is the failure of the application logic to rigorously validate that the identity claiming the resource consumption or AI interaction matches the authenticated session context of the requesting user.\nAffected components include the request handling and authorization modules responsible for processing AI-related feature invocations across GitLab EE namespaces.\nThe vulnerable version range encompasses all deployments of GitLab EE from 19.1 before 19.1.4 and from 19.2 before 19.2.2.\nAuthentication is required to execute the attack, as the actor must possess a valid user account to interact with the application and submit requests to the vulnerable endpoints.\nPrivilege requirements are minimal; any standard authenticated user who can interface with AI-enabled features can potentially supply arbitrary identity information.\nThe attack flow proceeds as follows: First, the authenticated attacker initiates a request to utilize AI features within the GitLab EE environment. Second, during the request construction or transmission phase, the attacker modifies the identity information or namespace parameters supplied in the request payload or headers. Third, the backend service processes the request without adequately verifying whether the submitting user possesses authorization to bind the operation to the specified target namespace. Consequently, the application attributes the AI usage metrics, computational overhead, and associated transactional data to the victim namespace rather than the attacker's namespace.\nPost-exploitation impact is characterized by inaccurate usage telemetry, potential financial or quota implications for the victim namespace due to consumption metrics being improperly reassigned, and integrity violations within the AI usage tracking subsystems."
}
CVE-2026-19228: GitLab Namespace Identity Authorization Bypass (HIGH Severity, CVSS: 8.5) - Sceawere