A vulnerability was found in GitLab up to 19.0.5/19.1.3/19.2.1. It has been declared as problematic. This vulnerability affects unknown code of the component Package Registry. Such manipulation leads to improper privilege management.

This vulnerability is referenced as CVE-2026-8667. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.