---
id: CVE-2026-2104
title: >-
  GitLab has remediated an issue in GitLab CE/EE affecting all versions from
  18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could
  have allowed an authenticated user to access confidential issues assigned to
  other use…
summary: >-
  GitLab has remediated an issue in GitLab CE/EE affecting all versions from
  18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could
  have allowed an authenticated user to access confidential issues assigned to
  other use…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: gitlab
product: gitlab
affected:
  - 'gitlab >= 18.2.0, < 18.8.9'
  - 'gitlab >= 18.9.0, < 18.9.5'
  - 'gitlab >= 18.10.0, < 18.10.3'
patched:
  - gitlab 18.10.3
published: '2026-04-08'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2104'
references:
  - url: >-
      https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/
    label: cve@gitlab.com
  - url: 'https://gitlab.com/gitlab-org/gitlab/-/work_items/589021'
    label: cve@gitlab.com
  - url: 'https://hackerone.com/reports/3541476'
    label: cve@gitlab.com
tags:
  - nvd
epss: 0.00308
epssPercentile: 0.23806
ingestedAt: '2026-07-26T10:11:58.818Z'
---

## Overview

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other users via CSV export due to insufficient authorization checks.

## Affected

- `gitlab >= 18.2.0, < 18.8.9`
- `gitlab >= 18.9.0, < 18.9.5`
- `gitlab >= 18.10.0, < 18.10.3`

## Remediation

Upgrade past the affected range:

- `gitlab 18.10.3`
