CVE-2026-6883
Last modified
CVE-2026-6883 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 15.7.0, < 18.9.7 |
| Gitlab | Gitlab | >= 18.10.0, < 18.10.6 |
| Gitlab | Gitlab | >= 18.11.0, < 18.11.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-6883?
How severe is CVE-2026-6883?
How do I fix CVE-2026-6883?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68821Improper privilege management in Windows Package Manager all…7.8
- CVE-2026-68823Exposed dangerous method or function in Azure Confidential L…9.1
- CVE-2026-68824Concurrent execution using shared resource with improper syn…7
- CVE-2026-68825Use after free in Windows Bind Filter Driver allows an autho…7
- CVE-2026-68827Integer underflow (wrap or wraparound) in Windows GDI+ allow…8
- CVE-2026-68828Heap-based buffer overflow in Remote Desktop Client allows a…8.8
- CVE-2026-68830Improper link resolution before file access ('link following…5.5
- CVE-2026-68831Files or directories accessible to external parties in Windo…5.5
- CVE-2026-68832Integer overflow or wraparound in Windows NTFS allows an aut…7.8
- CVE-2026-68833Heap-based buffer overflow in Windows NTFS allows an unautho…6.8
- CVE-2026-68834Stack-based buffer overflow in Windows NTFS allows an author…8
- CVE-2026-68835Use after free in Windows Print Spooler Components allows an…7.1
Are you affected by CVE-2026-6883?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
