Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-79708
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-79708 is an incorrect authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated users with developer-level permissions to execute policy test pipelines on group projects and access protected CI/CD variables restricted to higher-privileged roles. It affects GitLab EE versions 19.0 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. The vulnerability was published on September 16, 2026, and GitLab has released patches. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory).

Technical details

The root cause is insufficient scope validation during policy test pipeline execution, classified as CWE-863 (Incorrect Authorization). Under certain conditions, the authorization check performed when a developer-role user triggers a policy test pipeline does not correctly enforce role-based access controls, allowing the pipeline to access CI/CD variables that should be restricted to Maintainer or Owner roles. The attack is network-based, requires only low privileges (developer account), no user interaction, and results in a scope change — meaning the impact extends beyond the vulnerable component to protected variables across group projects. The vulnerability was reported via HackerOne (report #3873243) (GitHub Advisory).

Impact

A successful exploit allows an authenticated developer to retrieve protected CI/CD variables (e.g., API keys, secrets, deployment credentials) that are intended to be accessible only to Maintainers or Owners within a GitLab group. This represents a high integrity impact and low confidentiality impact per the CVSS scoring, with the scope change indicating that resources outside the developer's normal access boundary are affected. Exposure of CI/CD secrets could enable lateral movement into downstream infrastructure, supply chain compromise, or unauthorized deployments (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported at this time. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.34%, placing it in the 27th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a GitLab EE instance running a vulnerable version (19.0–19.1.7, 19.2–19.2.5, or 19.3–19.3.1) and obtain or possess a developer-level account within a group that has security policy projects configured.
  2. Identify target group: Locate a group project that uses GitLab Security Policy management and has protected CI/CD variables defined at the Maintainer/Owner scope.
  3. Trigger policy test pipeline: As a developer, invoke the policy test pipeline execution feature on a project within the group — a feature normally used to validate security policies.
  4. Access protected variables: Due to insufficient scope validation, the pipeline execution context grants access to protected CI/CD variables restricted to higher-privileged roles, exposing their values (e.g., via pipeline logs, environment variable dumps, or artifact output).
  5. Exfiltrate secrets: Retrieve the exposed CI/CD variable values (API tokens, cloud credentials, deployment keys) from pipeline output for use in further attacks (GitHub Advisory).

Indicators of compromise

  • Logs: GitLab application logs showing developer-role users triggering policy test pipelines on projects where they would not normally have access to protected variables; unexpected pipeline executions initiated by low-privilege accounts.
  • CI/CD Pipeline Activity: Policy test pipelines executed by developer accounts in groups with protected CI/CD variables — especially if the developer did not previously run such pipelines.
  • Audit Events: GitLab audit log entries for policy_test_pipeline_created or similar events associated with developer-role users accessing Maintainer/Owner-scoped variables.
  • Network: Outbound connections from CI/CD runners to unexpected external endpoints shortly after policy test pipeline execution, potentially indicating secret exfiltration.

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. Organizations running GitLab EE on affected versions (19.0–19.1.7, 19.2–19.2.5, 19.3–19.3.1) should upgrade to the respective patched release immediately. As a temporary workaround, administrators may consider restricting developer-role users from accessing security policy test pipeline features or auditing group-level CI/CD variable scoping until the patch can be applied (GitHub Advisory, GitLab Patch Release).

Community reactions

The vulnerability received coverage from several security news outlets including GBHackers, CyberPress, and UnderCodeNews, which reported on the broader GitLab 19.3.2 patch release addressing multiple critical flaws including arbitrary file read, credential theft, and remote code execution issues alongside CVE-2026-79708. Community discussion was noted on Infosec.exchange. The patch release was also covered by cicd.deployment.to and beyondmachines.net in the context of GitLab's emergency security update cycle (GitLab Patch Release).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79708HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-78252HIGH8.2
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-86341MEDIUM4.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-8030MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-7514MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management