
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-8030 is a Missing Authorization vulnerability in GitLab CE/EE that allows an authenticated user to prevent another user from modifying their group settings by exploiting improper validation of group URL slugs during namespace transfers. It affects all GitLab versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The vulnerability was published on September 16, 2026, and GitLab has released patches addressing the issue. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-862 (Missing Authorization), stemming from improper validation of group URL slugs during namespace transfer operations in GitLab. Under certain conditions, an authenticated user can craft or manipulate a namespace transfer request with a malformed or conflicting group URL slug, causing the target group's settings to become inaccessible or unmodifiable by its legitimate owner. Exploitation requires a low-privilege authenticated account and no user interaction, and is performed over the network with low attack complexity. The vulnerability was originally reported via HackerOne (report #3689558) (GitHub Advisory).
Successful exploitation results in a limited availability impact — specifically, a targeted denial of administrative capability where a legitimate group owner is prevented from modifying their own group settings. There is no confidentiality or integrity impact, and the scope is unchanged, meaning the effect is confined to the targeted group namespace. While not a critical system-wide compromise, this could disrupt group administration workflows and potentially be used to lock out administrators from managing access controls within their groups (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.414%, indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment notes exploitation as "none" and the attack as non-automatable (GitHub Advisory). No threat actor attribution has been reported.
GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. All users running GitLab CE/EE versions from 13.0 through 19.3.1 should upgrade to the appropriate patched release immediately. No configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation (GitLab Patch Release, GitHub Advisory).
The vulnerability received coverage from security news aggregators such as GBHackers and BeyondMachines shortly after disclosure, though no notable independent researcher commentary or significant community discussion has been identified. Coverage has been largely informational, reflecting the moderate severity and absence of active exploitation (GBHackers).
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"