CVE-2026-5377 is an access control vulnerability in GitLab Community and Enterprise Edition versions 18.11 before 18.11.1 that enables authenticated users to view titles of confidential or private issues in public projects through improper authorization checks in the issue description rendering process. The vulnerability affects a specific window of GitLab releases and has been remediated in version 18.11.1 and later. The vulnerability carries a CVSS v3.1 score of 4.3 (Medium severity) with a network-based attack vector requiring low complexity and valid user credentials, resulting in limited confidentiality impact without affecting integrity or availability. The attack requires low-privileged authenticated access and no user interaction to execute. There is currently no evidence of active exploitation in the wild, with no available public exploit code and no presence on the Known Exploited Vulnerabilities catalog. The vulnerability maintains a low profile within the security community, indicated by an EPSS score of 0.000120000 and an inactive status on vendor hotlists, suggesting minimal immediate threat to deployed systems once patched.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.11, < 18.11.1CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
18.11.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:* | ||
18.11.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.