Loading market data...
← Back to CVE feed

CVE-2026-2370

HIGH CVSS 8.1 View on NVD ↗

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected Products

gitlab/gitlab
Published: Mar 30, 2026 00:16 UTC Modified: Mar 30, 2026 15:44 UTC