
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7492 is an information disclosure vulnerability in GitLab CE/EE caused by improper authorization controls on cross-project reference pages. Under certain conditions, it allows an unauthenticated user to determine the existence of a private project. The vulnerability affects all GitLab CE/EE versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2. It was disclosed on July 8, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, or 4.3 (Moderate) per the GitHub Advisory (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-862 (Missing Authorization) — the application fails to perform an adequate authorization check when an unauthenticated actor accesses cross-project reference pages, inadvertently revealing whether a private project exists. The attack vector is network-based with low complexity and requires no privileges or user interaction, making it trivially accessible to any external attacker. The flaw is conditional, meaning specific circumstances must be present (e.g., a cross-project reference pointing to a private project) for the information to be disclosed (GitHub Advisory, Red Hat Bugzilla). The original report was submitted via HackerOne (report #3704739) (GitHub Advisory).
Successful exploitation allows an unauthenticated attacker to confirm the existence of private GitLab projects that should not be visible to them, constituting a confidentiality breach of organizational structure and project metadata. While no code execution, data modification, or service disruption is possible through this vulnerability alone, the disclosed information could be leveraged for reconnaissance — enabling targeted social engineering, phishing, or chaining with other vulnerabilities. Integrity and availability are not impacted (GitHub Advisory, Red Hat Bugzilla).
namespace/project#issue_id or merge request references) pointing to potentially private projects.GitLab has released patched versions addressing this vulnerability: 18.11.7, 19.0.4, and 19.1.2 for both CE and EE editions. Administrators should upgrade to one of these versions as the primary remediation. No configuration-based workaround has been published; upgrading is the only recommended fix (GitLab Patch Release, GitHub Advisory).
The vulnerability was covered as part of a broader GitLab patch release that addressed eight security vulnerabilities, attracting moderate coverage from cybersecurity news outlets including CyberPress, CyberSecurityNews, and Cryptika. Coverage generally framed the release as a proactive security update rather than an emergency response, consistent with the medium severity rating. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability reporting (GitLab Patch Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."