
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-79708 is an incorrect authorization vulnerability in GitLab EE that allows authenticated users with developer-level permissions to execute policy test pipelines on group projects and access protected CI/CD variables restricted to higher-privileged roles. It affects GitLab EE versions 19.0 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. The vulnerability was published on September 16, 2026, and GitLab has released patches. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory, GitLab Patch Release).
The root cause is insufficient scope validation (CWE-863: Incorrect Authorization) during the execution of policy test pipelines in GitLab EE. Under certain conditions, the authorization check does not correctly enforce role-based access controls, allowing a developer-privileged user to trigger policy test pipelines on projects within their group and retrieve CI/CD variables that should only be accessible to Maintainer or Owner roles. The attack is network-based, requires low privileges (developer role), no user interaction, and results in a scope change — meaning the impact extends beyond the directly vulnerable component to other projects within the group (GitHub Advisory).
Successful exploitation allows an authenticated developer to access protected CI/CD variables (such as secrets, API keys, deployment credentials, or tokens) that are restricted to higher-privileged roles, resulting in a high integrity impact and low confidentiality impact. This privilege escalation could expose sensitive pipeline secrets across multiple projects within a group, potentially enabling lateral movement into downstream systems or cloud environments that rely on those credentials. Availability is not impacted (GitHub Advisory, GitLab Patch Release).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.34% (28th percentile), indicating a relatively low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and technical impact as "partial." The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
policy_test_pipeline actions initiated by users with Developer role on group projects they do not own or maintain.GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. Organizations running GitLab EE on affected versions (19.0–19.1.7, 19.2–19.2.5, 19.3–19.3.1) should upgrade to one of these fixed releases immediately. No configuration-based workaround has been published; upgrading is the recommended remediation. As an interim measure, administrators may consider reviewing and auditing developer-role memberships in groups with sensitive protected CI/CD variables (GitLab Patch Release, GitHub Advisory).
The vulnerability was covered by several security news outlets including CyberPress, GBHackers, and Undercode News as part of broader coverage of GitLab's September 2026 patch release, which addressed multiple critical flaws. Community discussion on Mastodon (infosec.exchange) noted the patch release. Coverage generally highlighted the risk of CI/CD secret exposure and the importance of prompt patching in GitLab EE environments (GitLab Patch Release).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"