
PEACH
Un framework di isolamento del tenant
CVE-2026-8937 is a missing authorization vulnerability in GitLab CE/EE that allows authenticated users to read private child issue contents — including titles and descriptions — from projects they have no access to. The flaw affects all GitLab CE/EE versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. It was published on September 29, 2026, and has a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Feedly).
The root cause is a missing authorization check (CWE-862) on linked work items within visible epics. When an authenticated user can view an epic, the application fails to verify whether that user has access to child issues linked within the epic that belong to private or restricted projects. An attacker with low-level authenticated access can exploit this over the network with low complexity and no user interaction required, by navigating to a visible epic and accessing linked child issue data from projects they are not authorized to view (GitHub Advisory, Feedly).
Successful exploitation results in unauthorized disclosure of private issue titles and descriptions from projects the attacker has no legitimate access to. The impact is limited to confidentiality — there is no integrity or availability impact. While the exposed data is scoped to issue metadata rather than source code or credentials, sensitive project planning information, internal discussions, or security-related issue details could be exposed, potentially aiding further targeted attacks (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.263%, placing it in the 16th percentile for exploitation likelihood within 30 days (GitHub Advisory). The NVD SSVC assessment also classifies exploitation as "none" at this time.
/groups/<group>/-/epics/<id>) for epics in projects they do not belong to.GitLab has released patched versions addressing this vulnerability: 19.2.7, 19.3.3, and 19.4.1. Administrators should upgrade to one of these versions as soon as possible. No configuration-based workaround is available; upgrading is the only remediation. GitLab Cloud (GitLab.com) is managed by GitLab and would have been patched automatically (GitLab Patch Release, GitHub Advisory).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."