CVE-2026-10518: 
GitLab Schwachstellenanalyse und -minderung

Überblick

CVE-2026-10518 is an improper authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated users with guest-level permissions to read private security policy content they are not authorized to access. It affects all GitLab EE versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The vulnerability was published on September 29, 2026, and has been remediated by GitLab. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).

Technische Details

The root cause is classified as CWE-863 (Incorrect Authorization), where the authorization check performed when a guest-level user attempts to access private security policy content does not correctly enforce access restrictions under certain conditions. The attack vector is network-based, requires low privileges (a valid authenticated account with guest access), no user interaction, and low attack complexity. No specific technical write-ups or public proof-of-concept code have been identified for this vulnerability (GitHub Advisory).

Aufprall

Successful exploitation allows an authenticated guest-level user to read private security policy content that should be restricted to higher-privileged roles. The impact is limited to confidentiality — there is no integrity or availability impact. Exposure of security policy details could reveal an organization's internal security controls, compliance posture, or vulnerability management strategies to unauthorized users, potentially aiding further targeted attacks (GitHub Advisory, GitLab Patch Release).

Ausnutzbarkeit

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-10518. The EPSS score is approximately 0.33% (24th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" at this time (GitHub Advisory).

Risikominderung und Problemumgehungen

GitLab has released patched versions addressing this vulnerability. Users should upgrade to GitLab EE 19.2.7 (for versions 17.9–19.2.x), 19.3.3 (for 19.3.x), or 19.4.1 (for 19.4.x) or later. As interim measures, administrators should review audit logs for guest users who may have accessed sensitive security policy content and restrict guest account permissions where possible until patching is completed (GitLab Patch Release, GitHub Advisory).

Zusätzliche Ressourcen


Quelle: Dieser Bericht wurde mithilfe von KI erstellt

Verwandt GitLab Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NeinJaSep 24, 2026
CVE-2026-84739HIGH8.7
  • GitLab logoGitLab
  • gitlab
NeinJaSep 29, 2026
CVE-2026-8937MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
NeinJaSep 29, 2026
CVE-2026-10518MEDIUM4.3
  • GitLab logoGitLab
  • gitlab
NeinJaSep 29, 2026
CVE-2026-4523LOW3.7
  • GitLab logoGitLab
  • gitlab-rails-19.4
NeinJaSep 29, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement