GitLab GitLab Version Control Server
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any GitLab product.
RSS Feeds for GitLab security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in GitLab products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by GitLab Sorted by Most Security Vulnerabilities since 2018
Known Exploited GitLab Vulnerabilities
The following GitLab vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| GitLab Server-Side Request Forgery (SSRF) Vulnerability |
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. CVE-2021-22175 Exploit Probability: 53.4% |
February 18, 2026 |
| GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability |
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. CVE-2021-39935 Exploit Probability: 35.6% |
February 3, 2026 |
| GitLab Community and Enterprise Editions Improper Access Control Vulnerability |
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover. CVE-2023-7028 Exploit Probability: 94.6% |
May 1, 2024 |
The vulnerability CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. 2 known exploited GitLab vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 165 vulnerabilities in GitLab with an average score of 5.7 out of ten. Last year, in 2025 GitLab had 162 security vulnerabilities published. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.37
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 165 | 5.72 |
| 2025 | 162 | 6.09 |
| 2024 | 147 | 6.35 |
| 2023 | 183 | 5.60 |
| 2022 | 152 | 5.75 |
| 2021 | 157 | 5.44 |
| 2020 | 237 | 6.15 |
| 2019 | 165 | 6.33 |
| 2018 | 33 | 6.71 |
It may take a day or so for new GitLab vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent GitLab Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-14562 | Jul 29, 2026 |
GitLab CE/EE auth bypass via MR collaboration settings, before 19.2.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after being removed as a member, due to improper authorization checks on merge request collaboration settings. |
|
| CVE-2026-3093 | Jul 29, 2026 |
GitLab JavaScript XSS via crafted URL (v14.019.2.1)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input. |
|
| CVE-2026-4672 | Jul 29, 2026 |
GitLab Access Control Bypass in test reports CE/EE 18.4-19.2.1 (CVE-2026-4672)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were not authorized to view due to improper access control enforcement. |
|
| CVE-2026-6267 | Jul 29, 2026 |
GitLab CE/EE <=19.0.5 Dev Access Info Disclosure via Internal RequestsGitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling. |
|
| CVE-2026-6336 | Jul 29, 2026 |
Unauthorized Access: GitLab CE/EE v16.6-19.2.1 Project Import DisclosureGitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing authorization check. |
|
| CVE-2026-12436 | Jul 29, 2026 |
GitLab CE/EE <19.0.5/19.1.3/19.2.1 CI/CD Config Escalation via Pipeline ScheduleGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs. |
|
| CVE-2026-13113 | Jul 29, 2026 |
GitLab EE Merge race (pre-19.0.5) allows approvals bypassGitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing. |
|
| CVE-2026-14341 | Jul 29, 2026 |
GitLab API Auth Bypass: Maintainer Can Alter Protected Branches v12.819.2GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API endpoint. |
|
| CVE-2026-14351 | Jul 29, 2026 |
GitLab CE/EE 8.819.2.1 Unauth Issue Title Leak via MRGitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly accessible merge request due to improper authorization checks. |
|
| CVE-2026-15077 | Jul 29, 2026 |
GitLab EE Unauthorized Data Leak via AI Code Review (v19.1<19.1.3 & 19.2<19.2.1)GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality. |
|
| CVE-2026-15831 | Jul 29, 2026 |
GitLab EE Auth Bypass in Token Generation (19.1 < 19.1.3, 19.2 < 19.2.1)GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation. |
|
| CVE-2026-15975 | Jul 29, 2026 |
GitLab CE/EE 19.0.5/19.1<3.3 Unauth DoS via MR DiscussionsGitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling when processing merge request discussions. |
|
| CVE-2026-16553 | Jul 29, 2026 |
GitLab EE Virtual Reg Info Disclosure (18.819.2)GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of upstream requests in virtual registries. |
|
| CVE-2025-12506 | Jul 08, 2026 |
GitLab Repo Creation Web-Download Mismatch via Improper Git Ref (18.11.7)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web interface differed from the content available for download, due to improper handling of Git reference name resolution. |
|
| CVE-2026-6352 | Jul 08, 2026 |
GitLab EE Auth Bypass: Auditors can alter compliance records via GraphQLGitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with auditor-level access to modify compliance violation records due to improper authorization on certain GraphQL operations. |
|
| CVE-2026-6896 | Jul 08, 2026 |
GitLab EE: Arbitrary Script Exec via XSS in EE <18.11.7,<19.0.4,<19.1.2GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input. |
|
| CVE-2026-7492 | Jul 08, 2026 |
GitLab <=18.11.6 Unauth Detect Private Projects via Cross-Project Ref checkGitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an unauthenticated user to determine the existence of a private project due to improper authorization controls on cross-project reference pages. |
|
| CVE-2026-8472 | Jul 08, 2026 |
Auth Bypass: GitLab EE 18.9-18.11.7/19.0-19.0.4/19.1-19.1.2 Reading MetadataGitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private projects due to missing authorization checks. |
|
| CVE-2026-11827 | Jul 08, 2026 |
GitLab EE Auth Bypass: Maintainer Can Read Stored Credentials (v<18.11.7, 19.0<19.0.4, 19.1<19.1.2)GitLab has remediated an issue in GitLab EE affecting all versions from 9.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to obtain another user's stored credentials due to improper authorization controls. |
|
| CVE-2026-13151 | Jul 08, 2026 |
Auth Bypass Enables Priv Esc in GitLab EE 16.1018.11.7 / 19.019.0.4 / 19.119.1.2 |
|
| CVE-2026-13320 | Jul 08, 2026 |
GitLab CE/EE XSS: Authenticated exec via improper sanitization (18.11.7, 19.1.2)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input. |
|
| CVE-2026-10086 | Jun 25, 2026 |
GitLab EE 18.11.6/19.0.3/19.1.1: Dev role XSS via code execGitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input. |
|
| CVE-2026-0934 | Jun 25, 2026 |
GitLab EE: Auth Priv Access to Env Configs (v17.9-18.11,19.0-19.0,19.1-19.1)GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations despite CI/CD visibility being disabled for the project. |
|
| CVE-2026-1606 | Jun 25, 2026 |
GitLab CE/EE Snippet Escalation (18.11.5, 19.0.2, 19.1.0)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation. |
|
| CVE-2026-2238 | Jun 25, 2026 |
GitLab CE/EE <18.11.6/19.0.3/19.1.1 Unauthorized Confidential Issue Ref AccessGitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks. |
|
| CVE-2026-3176 | Jun 25, 2026 |
GitLab EE 18.618.11.5/19.0/19.1 AuthZ Bypass (Limited Auth)GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization checks. |
|
| CVE-2026-5309 | Jun 25, 2026 |
Unauth Access to GitLab EE Virtual Registry Cleanup Policy (18.11.6, 19.1.1)GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without authorization. |
|
| CVE-2026-5796 | Jun 25, 2026 |
GitLab CE/EE Pkg Reg Metadata View Bypass (13.6-18.11.5,19.0-19.0.2,19.1-19.1.0)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Package Registry disabled due to incorrect authorization checks in the group packages feature. |
|
| CVE-2026-5952 | Jun 25, 2026 |
GitLab <18.11.6, <19.0.3, <19.1.1: Dev Auth Bypass Pkg Protect, Overwrite Mvn MetaGitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks. |
|
| CVE-2026-8330 | Jun 25, 2026 |
GitLab CI/CD Log Disclosure via API (before 18.11.6, <19.0.3, <19.1.1)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI/CD API endpoint. |
|
| CVE-2026-10712 | Jun 25, 2026 |
GitLab CE/EE XSS via Improper Path Validation (18.11.5/19.0.2/19.1.0)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions. |
|
| CVE-2026-11379 | Jun 25, 2026 |
GitLab EE Auth Bypass in DAST Site Profile (<18.11.6, <19.0.3, <19.1.1)GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain conditions. |
|
| CVE-2026-12053 | Jun 25, 2026 |
GitLab EE <19.1.1 Improper Output Filtering in Duo Workflows Allows Sensitive Data LeakGitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows. |
|
| CVE-2026-12635 | Jun 25, 2026 |
GitLab Mirror Sync URL Validation flaw (8.318.11.5 & 19.x before patch)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mirror synchronization due to improper URL validation. |
|
| CVE-2026-1500 | Jun 11, 2026 |
GitLab DoS via Uncontrolled Resource Consumption on File Upload (17.1018.10.8, 18.1118.11.5, 19.019.GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to cause denial of service due to uncontrolled resource consumption when processing a specially crafted file upload. |
|
| CVE-2026-3553 | Jun 11, 2026 |
GitLab CE/EE <=18.10.8 Auth Bypass Exposes Issue DetailsGitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks. |
|
| CVE-2026-6269 | Jun 11, 2026 |
GitLab Auth Bypass on Hidden MRs (v15.1019.0)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to modify hidden merge requests due to incorrect authorization enforcements. |
|
| CVE-2026-6277 | Jun 11, 2026 |
Auth Bypass in GitLab EE 13.9-18.10.8,18.11-18.11.5,19.0-19.0.2 (SM Role)GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with Security Manager-role permissions to manage project security configuration even when the relevant feature was in a disabled state, due to incorrect authorization enforcement. |
|
| CVE-2026-6552 | Jun 11, 2026 |
Improper Auth in GitLab EE Group SAML (v15.518.10.8, 18.1118.11.5, 19.019.0.2) Owner Takeover |
|
| CVE-2026-6976 | Jun 11, 2026 |
GitLab CE/EE v15.9-18.10.8/18.11.5/19.0-19.0.2 Auth Dev Hide MR DiffGitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to hide changes from merge request diff views due to improper input handling of file names. |
|
| CVE-2026-7250 | Jun 11, 2026 |
GitLab API Middleware DoS vulnerability before v18.11.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper input validation in the API request parsing middleware. |
|
| CVE-2026-8589 | Jun 11, 2026 |
GitLab EE: Unauth email addition via flawed sanitization, fixed in 19.0.2GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields. |
|
| CVE-2026-9204 | Jun 11, 2026 |
GitLab CE/EE 18.10-19.0: Auth File Read via Bad Sec URL ValidationGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to read arbitrary files from the Gitaly server and access internal network resources during repository import, due to insufficient validation of secondary URLs. |
|
| CVE-2026-9694 | Jun 11, 2026 |
Unauth GitLab Support Bot Impersonation via Service Desk Email CVE-2026-9694GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply due to improper neutralization in email template processing. |
|
| CVE-2026-10087 | Jun 11, 2026 |
GitLab EE up to 18.10.7, 18.11.4, 19.0.1 XSS via Analytics DashboardGitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. |
|
| CVE-2026-10733 | Jun 11, 2026 |
GitLab CI/CD Catalog DoS via Improper Sanitization (v17.0-<18.10.8/18.11-<18.11.5/19.0-<19.0.2)GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause denial of service on the CI/CD Catalog page due to improper sanitization. |
|
| CVE-2026-9807 | May 28, 2026 |
GitLab auth allows blocked PAT to access resources before 18.10.7/18.11.4/19.0.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed a blocked Project Access Token to continue accessing private resources due to incorrect authorization enforcement. |
|
| CVE-2026-1402 | May 27, 2026 |
GitLab 17.1-18.10.7/18.11-18.11.4/19.0-19.0.1 Authenticated DoSGitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation. |
|
| CVE-2026-2601 | May 27, 2026 |
GitLab EE Auth Bypass: Dev Access to Deployment Data (<18.10.7, <18.11.4, <19.0.1)GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks. |
|
| CVE-2026-4868 | May 27, 2026 |
GitLab EE <18.10.7 / <18.11.4 / <19.0.1: Auth User Can Run Duo AI as Another UserGitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners. |
|