Detects GitLab CE/EE instances from 16.9.6 through 18.8.8, 18.9.0 through 18.9.4, and 18.10.0 through 18.10.2 where authenticated users can invoke restricted server-side methods through the /-/cable WebSocket endpoint's GraphqlChannel due to improper access control. A low-privileged user can enumerate private projects, user details, and internal configuration. Update to GitLab 18.8.9, 18.9.5, or 18.10.3.
Is your app exploitable through CVE-2026-5173?
Scan your domain free