Wiz tritt Google Cloud bei: Gemeinsam Magie erschaffen

CVE-2026-79708
GitLab Schwachstellenanalyse und -minderung

Überblick

CVE-2026-79708 is an incorrect authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated users with developer-level permissions to execute policy test pipelines on group projects and access protected CI/CD variables restricted to higher-privileged roles. It affects GitLab EE versions 19.0 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. The vulnerability was published on September 16, 2026, and GitLab has released patches. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory).

Technische Details

The root cause is insufficient scope validation during policy test pipeline execution, classified as CWE-863 (Incorrect Authorization). Under certain conditions, the authorization check performed when a developer-role user triggers a policy test pipeline does not correctly enforce role-based access controls, allowing the pipeline to access CI/CD variables that should be restricted to Maintainer or Owner roles. The attack is network-based, requires only low privileges (developer account), no user interaction, and results in a scope change — meaning the impact extends beyond the vulnerable component to protected variables across group projects. The vulnerability was reported via HackerOne (report #3873243) (GitHub Advisory).

Aufprall

A successful exploit allows an authenticated developer to retrieve protected CI/CD variables (e.g., API keys, secrets, deployment credentials) that are intended to be accessible only to Maintainers or Owners within a GitLab group. This represents a high integrity impact and low confidentiality impact per the CVSS scoring, with the scope change indicating that resources outside the developer's normal access boundary are affected. Exposure of CI/CD secrets could enable lateral movement into downstream infrastructure, supply chain compromise, or unauthorized deployments (GitHub Advisory).

Ausnutzbarkeit

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported at this time. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.34%, placing it in the 27th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Ausnutzungsschritte

  1. Reconnaissance: Identify a GitLab EE instance running a vulnerable version (19.0–19.1.7, 19.2–19.2.5, or 19.3–19.3.1) and obtain or possess a developer-level account within a group that has security policy projects configured.
  2. Identify target group: Locate a group project that uses GitLab Security Policy management and has protected CI/CD variables defined at the Maintainer/Owner scope.
  3. Trigger policy test pipeline: As a developer, invoke the policy test pipeline execution feature on a project within the group — a feature normally used to validate security policies.
  4. Access protected variables: Due to insufficient scope validation, the pipeline execution context grants access to protected CI/CD variables restricted to higher-privileged roles, exposing their values (e.g., via pipeline logs, environment variable dumps, or artifact output).
  5. Exfiltrate secrets: Retrieve the exposed CI/CD variable values (API tokens, cloud credentials, deployment keys) from pipeline output for use in further attacks (GitHub Advisory).

Indikatoren für Kompromittierung

  • Logs: GitLab application logs showing developer-role users triggering policy test pipelines on projects where they would not normally have access to protected variables; unexpected pipeline executions initiated by low-privilege accounts.
  • CI/CD Pipeline Activity: Policy test pipelines executed by developer accounts in groups with protected CI/CD variables — especially if the developer did not previously run such pipelines.
  • Audit Events: GitLab audit log entries for policy_test_pipeline_created or similar events associated with developer-role users accessing Maintainer/Owner-scoped variables.
  • Network: Outbound connections from CI/CD runners to unexpected external endpoints shortly after policy test pipeline execution, potentially indicating secret exfiltration.

Risikominderung und Problemumgehungen

GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. Organizations running GitLab EE on affected versions (19.0–19.1.7, 19.2–19.2.5, 19.3–19.3.1) should upgrade to the respective patched release immediately. As a temporary workaround, administrators may consider restricting developer-role users from accessing security policy test pipeline features or auditing group-level CI/CD variable scoping until the patch can be applied (GitHub Advisory, GitLab Patch Release).

Reaktionen der Community

The vulnerability received coverage from several security news outlets including GBHackers, CyberPress, and UnderCodeNews, which reported on the broader GitLab 19.3.2 patch release addressing multiple critical flaws including arbitrary file read, credential theft, and remote code execution issues alongside CVE-2026-79708. Community discussion was noted on Infosec.exchange. The patch release was also covered by cicd.deployment.to and beyondmachines.net in the context of GitLab's emergency security update cycle (GitLab Patch Release).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt GitLab Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-79708HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-78252HIGH8.2
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-86341MEDIUM4.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-8030MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026
CVE-2026-7514MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NeinJaSep 16, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement