
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-79708 is an incorrect authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated users with developer-level permissions to execute policy test pipelines on group projects and access protected CI/CD variables restricted to higher-privileged roles. It affects GitLab EE versions 19.0 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. The vulnerability was published on September 16, 2026, and GitLab has released patches. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory).
The root cause is insufficient scope validation during policy test pipeline execution, classified as CWE-863 (Incorrect Authorization). Under certain conditions, the authorization check performed when a developer-role user triggers a policy test pipeline does not correctly enforce role-based access controls, allowing the pipeline to access CI/CD variables that should be restricted to Maintainer or Owner roles. The attack is network-based, requires only low privileges (developer account), no user interaction, and results in a scope change — meaning the impact extends beyond the vulnerable component to protected variables across group projects. The vulnerability was reported via HackerOne (report #3873243) (GitHub Advisory).
A successful exploit allows an authenticated developer to retrieve protected CI/CD variables (e.g., API keys, secrets, deployment credentials) that are intended to be accessible only to Maintainers or Owners within a GitLab group. This represents a high integrity impact and low confidentiality impact per the CVSS scoring, with the scope change indicating that resources outside the developer's normal access boundary are affected. Exposure of CI/CD secrets could enable lateral movement into downstream infrastructure, supply chain compromise, or unauthorized deployments (GitHub Advisory).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported at this time. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.34%, placing it in the 27th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
policy_test_pipeline_created or similar events associated with developer-role users accessing Maintainer/Owner-scoped variables.GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. Organizations running GitLab EE on affected versions (19.0–19.1.7, 19.2–19.2.5, 19.3–19.3.1) should upgrade to the respective patched release immediately. As a temporary workaround, administrators may consider restricting developer-role users from accessing security policy test pipeline features or auditing group-level CI/CD variable scoping until the patch can be applied (GitHub Advisory, GitLab Patch Release).
The vulnerability received coverage from several security news outlets including GBHackers, CyberPress, and UnderCodeNews, which reported on the broader GitLab 19.3.2 patch release addressing multiple critical flaws including arbitrary file read, credential theft, and remote code execution issues alongside CVE-2026-79708. Community discussion was noted on Infosec.exchange. The patch release was also covered by cicd.deployment.to and beyondmachines.net in the context of GitLab's emergency security update cycle (GitLab Patch Release).
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"