
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-8030 is a Missing Authorization vulnerability in GitLab CE/EE that allows an authenticated user to prevent another user from modifying their group settings by exploiting improper validation of group URL slugs during namespace transfers. It affects all GitLab versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The vulnerability was published on September 16, 2026, and GitLab has released patches addressing the issue. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-862 (Missing Authorization), stemming from improper validation of group URL slugs during namespace transfer operations in GitLab. Under certain conditions, an authenticated user can craft or manipulate a namespace transfer request with a malformed or conflicting group URL slug, causing the target group's settings to become inaccessible or unmodifiable by its legitimate owner. Exploitation requires a low-privilege authenticated account and no user interaction, and is performed over the network with low attack complexity. The vulnerability was originally reported via HackerOne (report #3689558) (GitHub Advisory).
Successful exploitation results in a limited availability impact — specifically, a targeted denial of administrative capability where a legitimate group owner is prevented from modifying their own group settings. There is no confidentiality or integrity impact, and the scope is unchanged, meaning the effect is confined to the targeted group namespace. While not a critical system-wide compromise, this could disrupt group administration workflows and potentially be used to lock out administrators from managing access controls within their groups (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.414%, indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment notes exploitation as "none" and the attack as non-automatable (GitHub Advisory). No threat actor attribution has been reported.
GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. All users running GitLab CE/EE versions from 13.0 through 19.3.1 should upgrade to the appropriate patched release immediately. No configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation (GitLab Patch Release, GitHub Advisory).
The vulnerability received coverage from security news aggregators such as GBHackers and BeyondMachines shortly after disclosure, though no notable independent researcher commentary or significant community discussion has been identified. Coverage has been largely informational, reflecting the moderate severity and absence of active exploitation (GBHackers).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"