
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8030 is a Missing Authorization vulnerability in GitLab CE/EE that allows an authenticated user to prevent another user from modifying their group settings by exploiting improper validation of group URL slugs during namespace transfers. It affects all GitLab versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The vulnerability was published on September 16, 2026, and GitLab has released patches addressing the issue. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-862 (Missing Authorization), stemming from improper validation of group URL slugs during namespace transfer operations in GitLab. Under certain conditions, an authenticated user can craft or manipulate a namespace transfer request with a malformed or conflicting group URL slug, causing the target group's settings to become inaccessible or unmodifiable by its legitimate owner. Exploitation requires a low-privilege authenticated account and no user interaction, and is performed over the network with low attack complexity. The vulnerability was originally reported via HackerOne (report #3689558) (GitHub Advisory).
Successful exploitation results in a limited availability impact — specifically, a targeted denial of administrative capability where a legitimate group owner is prevented from modifying their own group settings. There is no confidentiality or integrity impact, and the scope is unchanged, meaning the effect is confined to the targeted group namespace. While not a critical system-wide compromise, this could disrupt group administration workflows and potentially be used to lock out administrators from managing access controls within their groups (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.414%, indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment notes exploitation as "none" and the attack as non-automatable (GitHub Advisory). No threat actor attribution has been reported.
GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. All users running GitLab CE/EE versions from 13.0 through 19.3.1 should upgrade to the appropriate patched release immediately. No configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation (GitLab Patch Release, GitHub Advisory).
The vulnerability received coverage from security news aggregators such as GBHackers and BeyondMachines shortly after disclosure, though no notable independent researcher commentary or significant community discussion has been identified. Coverage has been largely informational, reflecting the moderate severity and absence of active exploitation (GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."