CVE-2026-79708: 
GitLab 脆弱性の分析と軽減

概要

CVE-2026-79708 is an incorrect authorization vulnerability in GitLab EE that allows authenticated users with developer-level permissions to execute policy test pipelines on group projects and access protected CI/CD variables restricted to higher-privileged roles. It affects GitLab EE versions 19.0 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. The vulnerability was published on September 16, 2026, and GitLab has released patches. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory, GitLab Patch Release).

技術的な詳細

The root cause is insufficient scope validation (CWE-863: Incorrect Authorization) during the execution of policy test pipelines in GitLab EE. Under certain conditions, the authorization check does not correctly enforce role-based access controls, allowing a developer-privileged user to trigger policy test pipelines on projects within their group and retrieve CI/CD variables that should only be accessible to Maintainer or Owner roles. The attack is network-based, requires low privileges (developer role), no user interaction, and results in a scope change — meaning the impact extends beyond the directly vulnerable component to other projects within the group (GitHub Advisory).

影響

Successful exploitation allows an authenticated developer to access protected CI/CD variables (such as secrets, API keys, deployment credentials, or tokens) that are restricted to higher-privileged roles, resulting in a high integrity impact and low confidentiality impact. This privilege escalation could expose sensitive pipeline secrets across multiple projects within a group, potentially enabling lateral movement into downstream systems or cloud environments that rely on those credentials. Availability is not impacted (GitHub Advisory, GitLab Patch Release).

エクスプロイト可能性

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.34% (28th percentile), indicating a relatively low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and technical impact as "partial." The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify a GitLab EE instance running a vulnerable version (19.0–19.1.7, 19.2–19.2.5, or 19.3–19.3.1) where the attacker holds at least Developer-level membership in a group.
  2. Identify target projects: Enumerate projects within the attacker's group that have security policy configurations and protected CI/CD variables assigned to Maintainer or Owner roles.
  3. Trigger policy test pipeline: Leverage the policy test pipeline execution feature — which is accessible to developers under certain conditions — to initiate a pipeline run on a target project within the group.
  4. Access protected variables: Due to insufficient scope validation, the policy test pipeline executes with access to protected CI/CD variables restricted to higher-privileged roles, exposing their values within the pipeline logs or environment.
  5. Exfiltrate secrets: Extract the exposed CI/CD variable values (e.g., API keys, cloud credentials, deployment tokens) from pipeline output for use in further attacks or lateral movement (GitHub Advisory).

妥協の兆候

  • Logs: GitLab audit logs showing a Developer-role user triggering policy test pipelines on projects where they would not normally have Maintainer/Owner access; unexpected pipeline executions initiated by lower-privileged accounts.
  • CI/CD Pipeline Activity: Policy test pipelines executed by developer accounts on projects with protected variables scoped to higher roles; pipeline jobs accessing variables outside the user's normal permission scope.
  • Network: Outbound connections from CI/CD runners to unexpected external endpoints shortly after policy test pipeline execution, potentially indicating credential exfiltration.
  • GitLab Events: Audit events referencing policy_test_pipeline actions initiated by users with Developer role on group projects they do not own or maintain.

軽減策と回避策

GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. Organizations running GitLab EE on affected versions (19.0–19.1.7, 19.2–19.2.5, 19.3–19.3.1) should upgrade to one of these fixed releases immediately. No configuration-based workaround has been published; upgrading is the recommended remediation. As an interim measure, administrators may consider reviewing and auditing developer-role memberships in groups with sensitive protected CI/CD variables (GitLab Patch Release, GitHub Advisory).

コミュニティの反応

The vulnerability was covered by several security news outlets including CyberPress, GBHackers, and Undercode News as part of broader coverage of GitLab's September 2026 patch release, which addressed multiple critical flaws. Community discussion on Mastodon (infosec.exchange) noted the patch release. Coverage generally highlighted the risk of CI/CD secret exposure and the importance of prompt patching in GitLab EE environments (GitLab Patch Release).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 GitLab 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
いいえはいSep 24, 2026
CVE-2026-92874MEDIUM5.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
いいえはいSep 24, 2026
CVE-2026-92530MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
いいえはいSep 24, 2026
CVE-2026-92529MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
いいえはいSep 24, 2026
CVE-2026-92628LOW3.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
いいえはいSep 24, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者