
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0602 is an improper access control vulnerability in GitLab CE/EE's snippet rendering process that allows authenticated users to disclose metadata from private issues, merge requests, epics, milestones, or commits. It affects all GitLab CE/EE versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2. The vulnerability was disclosed and patched on March 11, 2026, with a CVSS v3.1 base score of 4.3 (Medium) (GitLab Advisory, Red Hat CVE).
The root cause is improper filtering in the snippet rendering process (CWE-288: Authentication Bypass Using an Alternate Path or Channel), which fails to adequately restrict access to metadata associated with private GitLab objects. An authenticated attacker with low-level privileges can exploit this over the network without any user interaction by leveraging the snippet rendering pathway as an alternate channel to bypass normal access controls. The vulnerability was reported by researcher go7f0 through GitLab's HackerOne bug bounty program, and the internal issue is tracked at gitlab.com/gitlab-org/gitlab/-/work_items/585007 (GitLab Advisory).
Successful exploitation allows an authenticated user to read metadata — such as titles, identifiers, or other descriptive fields — from private issues, merge requests, epics, milestones, or commits in projects they should not have access to. The impact is limited to confidentiality (no integrity or availability impact), but exposure of private project metadata could facilitate reconnaissance, reveal sensitive project planning details, or aid in further targeted attacks against an organization's development pipeline (GitLab Advisory, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated session with low privileges, limiting opportunistic mass exploitation (GitLab Advisory, Red Hat CVE).
GitLab released patched versions on March 11, 2026: 18.7.6 (for installations on the 15.6–18.7.x branch), 18.8.6 (for 18.8.x), and 18.9.2 (for 18.9.x). All self-managed GitLab installations should be upgraded to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. As a temporary workaround if immediate patching is not feasible, consider restricting snippet rendering access or limiting authenticated user permissions (GitLab Advisory).
GitLab's patch release advisory strongly recommends immediate upgrade for all self-managed installations and notes the vulnerability was responsibly disclosed through their HackerOne bug bounty program by researcher go7f0. No significant independent researcher commentary or notable media coverage has been identified for this specific CVE, consistent with its medium severity rating and lack of active exploitation (GitLab Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."