---
id: CVE-2026-4398
title: >-
  GitLab has remediated an issue in GitLab EE affecting all versions from 18.3
  before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain
  conditions, an authenticated user could have assigned compliance frameworks
  from n…
summary: >-
  GitLab has remediated an issue in GitLab EE affecting all versions from 18.3
  before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain
  conditions, an authenticated user could have assigned compliance frameworks
  from n…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-639
published: '2026-04-08'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4398'
references:
  - url: >-
      https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/
    label: cve@gitlab.com
  - url: 'https://gitlab.com/gitlab-org/gitlab/-/work_items/600360'
    label: cve@gitlab.com
  - url: 'https://hackerone.com/reports/3549150'
    label: cve@gitlab.com
tags:
  - nvd
epss: 0.00242
epssPercentile: 0.15725
ingestedAt: '2026-08-29T00:27:52.434Z'
---

## Overview

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to access to their own project, due to missing namespace validation on self-managed instances.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
