CVE-2026-10518: 
GitLab Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-10518 is an improper authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated users with guest-level permissions to read private security policy content they are not authorized to access. It affects all GitLab EE versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The vulnerability was published on September 29, 2026, and has been remediated by GitLab. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).

Dettagli tecnici

The root cause is classified as CWE-863 (Incorrect Authorization), where the authorization check performed when a guest-level user attempts to access private security policy content does not correctly enforce access restrictions under certain conditions. The attack vector is network-based, requires low privileges (a valid authenticated account with guest-level access), no user interaction, and low attack complexity. The flaw is limited to GitLab EE and does not affect GitLab Community Edition. Technical details are referenced in the HackerOne report and the GitLab internal work item (GitHub Advisory, GitLab Issue).

Impatto

Successful exploitation allows an authenticated guest-level user to read private security policy content that should be restricted to higher-privileged roles. The impact is limited to confidentiality — there is no integrity or availability impact. Exposure of security policies could reveal internal security controls, compliance configurations, or vulnerability management strategies, potentially aiding further targeted attacks against the organization (GitHub Advisory).

Sfruttabilità

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed as of the publication date. The EPSS score is approximately 0.331% (24th percentile), indicating a low probability of exploitation in the near term. The NVD SSVC assessment classifies the vulnerability as non-automatable with partial technical impact. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, GitLab Patch Release).

Mitigazione e soluzioni alternative

GitLab has released patched versions to address this vulnerability. Users should upgrade to the following fixed versions based on their current release branch:

  • 17.9–19.2.x: Upgrade to 19.2.7 or later
  • 19.3.x: Upgrade to 19.3.3 or later
  • 19.4.x: Upgrade to 19.4.1 or later

As an interim measure, administrators should review and audit guest-level account permissions, restrict guest access where possible, and audit logs for any unauthorized access to security policy content. No configuration-based workaround has been officially documented (GitLab Patch Release, GitHub Advisory).

Risorse aggiuntive


Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale

Imparentato GitLab Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • gitlab-runner-19.3
NoSìSep 24, 2026
CVE-2026-84739HIGH8.7
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026
CVE-2026-8937MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026
CVE-2026-10518MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026
CVE-2026-4523LOW3.7
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità