CVE-2026-5173 is an access control vulnerability affecting GitLab Community Edition and Enterprise Edition across multiple versions (16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3). The flaw allows authenticated users to invoke unintended server-side methods through websocket connections due to improper access control mechanisms. The vulnerability carries a CVSS score of 8.5 (HIGH) with a network-based attack vector requiring low complexity and low privileges. The attack requires an authenticated user but no user interaction, with potential consequences including high confidentiality impact and limited integrity impact across multiple systems. The network-based nature and low attack complexity indicate this could be exploited by most attackers with valid credentials. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.00023 indicates this vulnerability ranks lower than most CVEs in terms of real-world exploitation probability, though organizations running affected GitLab versions should prioritize patching to prevent potential privilege escalation or lateral movement by authenticated threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.9.6, < 18.8.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.9.0, < 18.9.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.10.0, < 18.10.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.9.6, < 18.8.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 18.9.0, < 18.9.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.