
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-7514 is a missing authorization vulnerability in GitLab CE/EE's Generic Package Registry that allows authenticated users with developer-role permissions to substitute package file content and hide packages from their owners. It affects all GitLab versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The vulnerability was published on September 16, 2026, and GitLab has released patches. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-862 (Missing Authorization) — the Generic Package Registry fails to perform adequate authorization checks when a developer-role user attempts to modify or overwrite package file content belonging to other owners. An authenticated attacker with at least developer-level access can exploit this over the network with low complexity and no user interaction required, by sending crafted requests to the package registry API to overwrite existing package files or obscure package visibility from legitimate owners. The vulnerability was originally reported via HackerOne (HackerOne Report, GitHub Advisory).
Successful exploitation allows an authenticated developer-role user to tamper with package file content in the Generic Package Registry, potentially injecting malicious code or dependencies into packages consumed by other project members or CI/CD pipelines. Additionally, attackers can hide packages from their legitimate owners, disrupting visibility and auditability of the software supply chain. There is no direct confidentiality or availability impact, but the integrity risk to software artifacts and the potential for supply chain compromise within affected GitLab instances is notable (GitHub Advisory, GitLab Patch Release).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated access with developer-role permissions. The EPSS score is approximately 0.325%, placing it in the 26th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. All GitLab CE/EE installations running versions from 13.9 through the affected ranges should upgrade immediately. As an interim measure, administrators should review and restrict developer-role permissions on the Generic Package Registry and monitor package registry activity for unexpected modifications or hidden packages (GitLab Patch Release, GitHub Advisory).
GBHackers covered the vulnerability as part of a broader report on GitLab flaws shortly after disclosure. Beyond Machines also noted the patch release in the context of GitLab's September 2026 security updates. No significant researcher commentary or notable community debate has been identified beyond standard vulnerability tracking and aggregation (GBHackers, Beyond Machines).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"