
PEACH
Un framework di isolamento del tenant
CVE-2026-10518 is an improper authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated users with guest-level permissions to read private security policy content they are not authorized to access. It affects all GitLab EE versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The vulnerability was published on September 29, 2026, and has been remediated by GitLab. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-863 (Incorrect Authorization), where the authorization check performed when a guest-level user attempts to access private security policy content does not correctly enforce access restrictions under certain conditions. The attack vector is network-based, requires low privileges (a valid authenticated account with guest-level access), no user interaction, and low attack complexity. The flaw is limited to GitLab EE and does not affect GitLab Community Edition. Technical details are referenced in the HackerOne report and the GitLab internal work item (GitHub Advisory, GitLab Issue).
Successful exploitation allows an authenticated guest-level user to read private security policy content that should be restricted to higher-privileged roles. The impact is limited to confidentiality — there is no integrity or availability impact. Exposure of security policies could reveal internal security controls, compliance configurations, or vulnerability management strategies, potentially aiding further targeted attacks against the organization (GitHub Advisory).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed as of the publication date. The EPSS score is approximately 0.331% (24th percentile), indicating a low probability of exploitation in the near term. The NVD SSVC assessment classifies the vulnerability as non-automatable with partial technical impact. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, GitLab Patch Release).
GitLab has released patched versions to address this vulnerability. Users should upgrade to the following fixed versions based on their current release branch:
As an interim measure, administrators should review and audit guest-level account permissions, restrict guest access where possible, and audit logs for any unauthorized access to security policy content. No configuration-based workaround has been officially documented (GitLab Patch Release, GitHub Advisory).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."