CVE-2026-8937: 
GitLab Schwachstellenanalyse und -minderung

Überblick

CVE-2026-8937 is a missing authorization vulnerability in GitLab CE/EE that allows authenticated users to read private child issue contents — including titles and descriptions — from projects they have no access to. The flaw affects all GitLab CE/EE versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. It was published on September 29, 2026, and has a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).

Technische Details

The root cause is a missing authorization check (CWE-862) on linked work items within visible epics. When an authenticated user can view an epic, GitLab failed to verify whether that user had access to the child issues linked within that epic, allowing unauthorized read access to private issue titles and descriptions from restricted projects. The vulnerability was reported via HackerOne (report #3702369) and tracked internally at GitLab work item #600533. No public proof-of-concept code has been published (GitHub Advisory, GitLab Patch Release).

Aufprall

Successful exploitation allows an authenticated attacker with low privileges to read confidential issue titles and descriptions from GitLab projects they are not authorized to access. The impact is limited to confidentiality — there is no integrity or availability impact — and does not enable code execution, lateral movement, or access to repository contents beyond issue metadata. Organizations using GitLab for sensitive project management (e.g., security tracking, internal roadmaps) may be at risk of information disclosure through this vector (GitHub Advisory).

Ausnutzbarkeit

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of publication. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.263% (17th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Ausnutzungsschritte

  1. Authenticate: Log in to a vulnerable GitLab instance (versions 19.0–19.2.6, 19.3.0–19.3.2, or 19.4.0) with any valid low-privilege user account.
  2. Identify accessible epics: Browse or search for epics in groups or projects the authenticated user has at least read access to.
  3. Enumerate linked work items: Within a visible epic, identify child issues that are linked from private or restricted projects.
  4. Access restricted issue content: Due to the missing authorization check, the API or UI may return the title and description of private child issues from projects the user has no access to, exposing confidential information.

Indikatoren für Kompromittierung

  • Logs: GitLab application logs showing authenticated users accessing epic work item endpoints (e.g., /groups/:group/-/epics/:epic_id or related GraphQL queries) for epics containing cross-project linked issues, particularly from accounts with minimal project memberships.
  • Audit Events: GitLab audit log entries for users reading issue details from projects they are not members of, which may appear anomalous when correlated with project membership records.
  • Network: Unusual API calls to GitLab's GraphQL or REST endpoints for work items/epics from accounts that do not have membership in the referenced child issue projects.

Risikominderung und Problemumgehungen

GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. All GitLab CE/EE administrators running affected versions (19.0.x through 19.2.6, 19.3.0–19.3.2, or 19.4.0) should upgrade to one of these fixed releases immediately. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Patch Release, GitHub Advisory).

Zusätzliche Ressourcen


Quelle: Dieser Bericht wurde mithilfe von KI erstellt

Verwandt GitLab Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NeinJaSep 24, 2026
CVE-2026-84739HIGH8.7
  • GitLab logoGitLab
  • gitlab
NeinJaSep 29, 2026
CVE-2026-8937MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
NeinJaSep 29, 2026
CVE-2026-10518MEDIUM4.3
  • GitLab logoGitLab
  • gitlab
NeinJaSep 29, 2026
CVE-2026-4523LOW3.7
  • GitLab logoGitLab
  • gitlab-rails-19.4
NeinJaSep 29, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement