CVE-2026-7492
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-7492 is an information disclosure vulnerability in GitLab CE/EE caused by improper authorization controls on cross-project reference pages. Under certain conditions, it allows an unauthenticated user to determine the existence of a private project. The vulnerability affects all GitLab CE/EE versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2. It was disclosed on July 8, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, or 4.3 (Moderate) per the GitHub Advisory (GitHub Advisory, GitLab Patch Release).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the application fails to perform an adequate authorization check when an unauthenticated actor accesses cross-project reference pages, inadvertently revealing whether a private project exists. The attack vector is network-based with low complexity and requires no privileges or user interaction, making it trivially accessible to any external attacker. The flaw is conditional, meaning specific circumstances must be present (e.g., a cross-project reference pointing to a private project) for the information to be disclosed (GitHub Advisory, Red Hat Bugzilla). The original report was submitted via HackerOne (report #3704739) (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to confirm the existence of private GitLab projects that should not be visible to them, constituting a confidentiality breach of organizational structure and project metadata. While no code execution, data modification, or service disruption is possible through this vulnerability alone, the disclosed information could be leveraged for reconnaissance — enabling targeted social engineering, phishing, or chaining with other vulnerabilities. Integrity and availability are not impacted (GitHub Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Reconnaissance: Identify a publicly accessible GitLab instance running a vulnerable version (9.1 through 18.11.6, 19.0.0–19.0.3, or 19.1.0–19.1.1) using version fingerprinting via the GitLab API or login page metadata.
  2. Identify cross-project references: Browse public projects or issues that contain cross-project references (e.g., namespace/project#issue_id or merge request references) pointing to potentially private projects.
  3. Access cross-project reference pages: As an unauthenticated user, navigate to the cross-project reference page URL associated with the referenced private project.
  4. Observe response: Analyze the HTTP response — a response that reveals project-specific metadata or a non-generic error (rather than a generic 404) confirms the private project exists, disclosing its existence to the unauthenticated attacker (GitHub Advisory, GitLab Patch Release).

Indicators of compromise

  • Network: Unusual volume of unauthenticated HTTP GET requests to GitLab cross-project reference URLs (e.g., paths containing cross-project issue or merge request references) from a single IP or range.
  • Logs: GitLab application logs showing repeated unauthenticated access attempts to cross-project reference endpoints, particularly for projects that are private; look for 200 or non-404 responses to such requests from unauthenticated sessions.
  • Logs: Patterns of systematic enumeration — sequential or patterned requests to reference pages across many project namespaces from the same source IP within a short timeframe.

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: 18.11.7, 19.0.4, and 19.1.2 for both CE and EE editions. Administrators should upgrade to one of these versions as the primary remediation. No configuration-based workaround has been published; upgrading is the only recommended fix (GitLab Patch Release, GitHub Advisory).

Community reactions

The vulnerability was covered as part of a broader GitLab patch release that addressed eight security vulnerabilities, attracting moderate coverage from cybersecurity news outlets including CyberPress, CyberSecurityNews, and Cryptika. Coverage generally framed the release as a proactive security update rather than an emergency response, consistent with the medium severity rating. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability reporting (GitLab Patch Release).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6896MEDIUM5.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 08, 2026
CVE-2026-13320MEDIUM5.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 08, 2026
CVE-2026-7492MEDIUM5.3
  • GitLab logoGitLab
  • gitlab
NoYesJul 08, 2026
CVE-2026-8472MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 08, 2026
CVE-2026-6352LOW2.7
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management