Wiz tritt Google Cloud bei: Gemeinsam Magie erschaffen

CVE-2026-78252
GitLab Schwachstellenanalyse und -minderung

Überblick

CVE-2026-78252 is a Cross-Site Scripting (XSS) / Cross-Site Request Forgery (CSRF) vulnerability in GitLab CE/EE's Markdown JSON table renderer that allows an authenticated attacker to induce a targeted user to perform unintended state-changing HTTP requests. It affects all GitLab CE/EE versions from 15.3 before 19.1.8, versions 19.2 before 19.2.6, and versions 19.3 before 19.3.2. The vulnerability was published on September 16, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory, GitLab Patch Release).

Technische Details

The root cause is improper sanitization of user-controlled data within GitLab's Markdown JSON table renderer (CWE-79: Improper Neutralization of Input During Web Page Generation). An authenticated attacker can craft malicious Markdown content containing a JSON table that, when rendered and viewed by a targeted user, causes that user's browser to execute unintended state-changing HTTP requests — effectively a CSRF-via-XSS attack vector. Exploitation requires user interaction (the victim must view the malicious content) and has high attack complexity, but no privileges beyond authentication are required on the attacker's part. The vulnerability was originally reported via HackerOne report #3917471 (GitHub Advisory, GitLab Issue).

Aufprall

Successful exploitation allows an authenticated attacker to cause a targeted user's browser to perform unauthorized state-changing HTTP requests on their behalf, such as modifying account settings, creating or deleting resources, or changing permissions within GitLab. The vulnerability has high confidentiality and integrity impact with low availability impact, and its changed scope means effects can extend beyond the directly vulnerable component. This could enable privilege escalation, unauthorized repository access, or account takeover depending on the actions triggered (GitHub Advisory).

Ausnutzbarkeit

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation, as confirmed by NVD SSVC data indicating exploitation status of "none" (GitHub Advisory). The EPSS score is approximately 0.39%, placing it in the 33rd percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Qualys (ID: 388702) and Nessus (ID: 346269).

Ausnutzungsschritte

  1. Authenticate to GitLab: The attacker must have a valid GitLab account on the target instance (any role that can create Markdown content such as issues, merge requests, wikis, or comments).
  2. Craft malicious Markdown: Create a Markdown JSON table payload that embeds unsanitized content exploiting the renderer's improper input handling — for example, injecting JavaScript or crafted HTML attributes within a JSON table structure that triggers a state-changing HTTP request (e.g., a form submission or fetch call) when rendered.
  3. Deliver the payload: Post the malicious Markdown content in a location visible to the target user, such as an issue comment, merge request description, wiki page, or project README.
  4. Wait for victim interaction: When the targeted user views the page containing the malicious Markdown table, their browser renders the content and executes the embedded payload, causing an unintended HTTP request (e.g., changing settings, adding SSH keys, or modifying permissions) on the victim's behalf.
  5. Achieve objective: Depending on the crafted request, the attacker may gain elevated access, exfiltrate data, or perform destructive actions within the victim's GitLab session (GitHub Advisory, GitLab Issue).

Indikatoren für Kompromittierung

  • Logs: GitLab application logs showing unexpected state-changing requests (POST/PUT/DELETE) originating from user sessions shortly after viewing specific issues, MRs, or wiki pages; unusual account setting changes or SSH key additions in audit logs.
  • Network: HTTP requests to GitLab API endpoints (e.g., /api/v4/users, /api/v4/projects) that do not match expected user workflows, particularly triggered immediately after page loads containing Markdown content.
  • Application: Presence of suspicious Markdown content in issues, merge requests, or wikis containing JSON table structures with embedded JavaScript, event handlers, or external URL references; unexpected changes to user profiles, SSH keys, or project membership.

Risikominderung und Problemumgehungen

GitLab has released patched versions addressing this vulnerability: 19.1.8 (for the 15.3–19.1.x branch), 19.2.6 (for the 19.2.x branch), and 19.3.2 (for the 19.3.x branch). All GitLab CE/EE administrators should upgrade to one of these versions immediately. As a supplementary measure, administrators can restrict Markdown/table creation capabilities to trusted users and educate users to exercise caution when viewing content from less-trusted sources within GitLab (GitLab Patch Release, GitHub Advisory).

Reaktionen der Community

Security news outlets including GBHackers and The Arabian Post covered the GitLab patch release, with The Arabian Post noting GitLab issued "urgent patches" for critical flaws in the same release cycle (GBHackers, Arabian Post). Coverage was primarily focused on the broader September 2026 GitLab patch release, which also addressed a critical path traversal vulnerability (CVE-2026-85706) that received more prominent attention. No notable individual researcher commentary specific to CVE-2026-78252 has been identified.

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt GitLab Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-79708HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-78252HIGH8.2
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-86341MEDIUM4.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-8030MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-7514MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement