CVE-2026-44585: Paymenter has broken object level authorization via service reference manipulation on ticket creation
The ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to other accounts by modifying the service ID in the request.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-44585 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →