A vulnerability marked as problematic has been reported in GitLab Community Edition and Enterprise Edition up to 18.11.5/19.0.2/19.1.0. Affected by this issue is some unknown functionality of the component Public Project Handler. Performing a manipulation results in missing authorization.

This vulnerability is identified as CVE-2026-2238. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.