
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-8937 is a missing authorization vulnerability in GitLab CE/EE that allows authenticated users to read private child issue contents — including titles and descriptions — from projects they have no access to. The flaw affects all GitLab CE/EE versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. It was published on September 29, 2026, and has a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).
The root cause is a missing authorization check (CWE-862) on linked work items within visible epics. When an authenticated user can view an epic, GitLab failed to verify whether that user had access to the child issues linked within that epic, allowing unauthorized read access to private issue titles and descriptions from restricted projects. The vulnerability was reported via HackerOne (report #3702369) and tracked internally at GitLab work item #600533. No public proof-of-concept code has been published (GitHub Advisory, GitLab Patch Release).
Successful exploitation allows an authenticated attacker with low privileges to read confidential issue titles and descriptions from GitLab projects they are not authorized to access. The impact is limited to confidentiality — there is no integrity or availability impact — and does not enable code execution, lateral movement, or access to repository contents beyond issue metadata. Organizations using GitLab for sensitive project management (e.g., security tracking, internal roadmaps) may be at risk of information disclosure through this vector (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of publication. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.263% (17th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
/groups/:group/-/epics/:epic_id or related GraphQL queries) for epics containing cross-project linked issues, particularly from accounts with minimal project memberships.GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. All GitLab CE/EE administrators running affected versions (19.0.x through 19.2.6, 19.3.0–19.3.2, or 19.4.0) should upgrade to one of these fixed releases immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Patch Release, GitHub Advisory).
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"