
PEACH
Un cadre d’isolation des locataires
CVE-2026-6821 is an authorization bypass vulnerability in GitLab Enterprise Edition (EE) affecting all versions from 12.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2. Under certain conditions, an authenticated user could bypass IP-based access restrictions and read limited merge request information from private projects due to missing authorization checks in a merge requests API endpoint. The vulnerability was disclosed on August 12, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, ENISA EUVD).
The root cause is classified as CWE-862 (Missing Authorization) — the merge requests API endpoint fails to enforce IP-based access restriction checks under certain conditions, allowing requests that should be blocked to proceed. An authenticated low-privileged user can send network requests to the affected API endpoint to retrieve merge request metadata from private projects they should not have access to. No user interaction is required, and attack complexity is low, making the flaw straightforward to exploit once an attacker has any valid authenticated session (GitHub Advisory, ENISA EUVD).
Successful exploitation allows an authenticated attacker to read limited merge request information from private GitLab EE projects that are protected by IP-based access restrictions, resulting in a confidentiality impact. There is no integrity or availability impact — the vulnerability is limited to unauthorized read access of merge request data. While the exposed data is described as "limited," it could include sensitive code review discussions, branch names, or development context that aids further reconnaissance (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (ENISA EUVD). The EPSS score is approximately 0.281%, placing it in the 21st percentile for exploitation likelihood within 30 days. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 334981) and Qualys (plugin 388347) (GitHub Advisory).
GET /api/v4/projects/:id/merge_requests) for a private project that the attacker's IP address should be restricted from accessing./api/v4/projects/:id/merge_requests originating from IP addresses outside the configured IP allowlist for a private project.GitLab has released patched versions: 19.0.6, 19.1.4, and 19.2.2. Organizations should upgrade to the appropriate patched release as the primary remediation (GitLab Patch Release). As a temporary measure, administrators should review and audit API access logs to identify any unauthorized access to merge request endpoints during the exposure window, and consider strengthening IP-based access control policies. Reviewing which users have authenticated access to the GitLab instance can also reduce the attack surface while patching is underway (ENISA EUVD).
Security monitoring platforms including SecurityOnline.info covered the GitLab patch release, and the vulnerability was catalogued by ENISA's EUVD and VulDB shortly after disclosure. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking (ENISA EUVD).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."