A vulnerability categorized as problematic has been discovered in GitLab up to 19.0.5/19.1.3/19.2.1 . This affects an unknown function of the component Merge Requests API . The manipulation results in improper authorization. This vulnerability is identified as CVE-2026-6821 . The attack can be executed remotely. There is not any exploit available. It is advisable to upgrade the affected component.