A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been classified as problematic. This impacts an unknown function of the component Access Token Handler. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-9807. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.