Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5377

18
FAUCET Score

CVE-2026-5377 is an access control vulnerability in GitLab Community and Enterprise Edition versions 18.11 before 18.11.1 that enables authenticated users to view titles of confidential or private issues in public projects through improper authorization checks in the issue description rendering process. The vulnerability affects a specific window of GitLab releases and has been remediated in version 18.11.1 and later. The vulnerability carries a CVSS v3.1 score of 4.3 (Medium severity) with a network-based attack vector requiring low complexity and valid user credentials, resulting in limited confidentiality impact without affecting integrity or availability. The attack requires low-privileged authenticated access and no user interaction to execute. There is currently no evidence of active exploitation in the wild, with no available public exploit code and no presence on the Known Exploited Vulnerabilities catalog. The vulnerability maintains a low profile within the security community, indicated by an EPSS score of 0.000120000 and an inactive status on vendor hotlists, suggesting minimal immediate threat to deployed systems once patched.

Impacted Technologies

VendorProductVersion(s)CPE
>= 18.11, < 18.11.1CPE match
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
18.11.0CPE matchmatch criteria
cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*
18.11.0CPE matchmatch criteria
cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:enterprise:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 21st percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

about.gitlab.com / releases/2026/04/22/patch-release-gitlab-18-11-1-released
Release NotesVendor Advisory
gitlab.com / gitlab-org/gitlab/-/work_items/595553
Broken Link
hackerone.com / reports/3640688
Permissions Required