CVE-2026-0602
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-0602 is an improper access control vulnerability in GitLab CE/EE's snippet rendering process that allows authenticated users to disclose metadata from private issues, merge requests, epics, milestones, or commits. It affects all GitLab CE/EE versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2. The vulnerability was disclosed and patched on March 11, 2026, with a CVSS v3.1 base score of 4.3 (Medium) (GitLab Advisory, Red Hat CVE).

Technical details

The root cause is improper filtering in the snippet rendering process (CWE-288: Authentication Bypass Using an Alternate Path or Channel), which fails to adequately restrict access to metadata associated with private GitLab objects. An authenticated attacker with low-level privileges can exploit this over the network without any user interaction by leveraging the snippet rendering pathway as an alternate channel to bypass normal access controls. The vulnerability was reported by researcher go7f0 through GitLab's HackerOne bug bounty program, and the internal issue is tracked at gitlab.com/gitlab-org/gitlab/-/work_items/585007 (GitLab Advisory).

Impact

Successful exploitation allows an authenticated user to read metadata — such as titles, identifiers, or other descriptive fields — from private issues, merge requests, epics, milestones, or commits in projects they should not have access to. The impact is limited to confidentiality (no integrity or availability impact), but exposure of private project metadata could facilitate reconnaissance, reveal sensitive project planning details, or aid in further targeted attacks against an organization's development pipeline (GitLab Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated session with low privileges, limiting opportunistic mass exploitation (GitLab Advisory, Red Hat CVE).

Mitigation and workarounds

GitLab released patched versions on March 11, 2026: 18.7.6 (for installations on the 15.6–18.7.x branch), 18.8.6 (for 18.8.x), and 18.9.2 (for 18.9.x). All self-managed GitLab installations should be upgraded to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. As a temporary workaround if immediate patching is not feasible, consider restricting snippet rendering access or limiting authenticated user permissions (GitLab Advisory).

Community reactions

GitLab's patch release advisory strongly recommends immediate upgrade for all self-managed installations and notes the vulnerability was responsibly disclosed through their HackerOne bug bounty program by researcher go7f0. No significant independent researcher commentary or notable media coverage has been identified for this specific CVE, consistent with its medium severity rating and lack of active exploitation (GitLab Advisory).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16553MEDIUM5.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 29, 2026
CVE-2026-6336MEDIUM5.3
  • GitLab logoGitLab
  • gitlab-rails-ce-18.8
NoYesJul 29, 2026
CVE-2026-6267MEDIUM5.3
  • GitLab logoGitLab
  • gitlab-rails-ce-fips-18.9
NoYesJul 29, 2026
CVE-2026-3093MEDIUM4.7
  • GitLab logoGitLab
  • gitlab-rails-ce-18.1
NoYesJul 29, 2026
CVE-2026-4672MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management