
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8472 is a missing authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated users with minimal access permissions to read work item metadata from private projects they should not have access to. It affects GitLab EE versions 18.9.0 through 18.11.6, 19.0.0 through 19.0.3, and 19.1.0 through 19.1.1. The vulnerability was disclosed and patched on July 8, 2026, with fixed versions released the same day. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-862 (Missing Authorization): GitLab EE fails to perform adequate authorization checks when an authenticated user attempts to access work item metadata in private projects. Under certain conditions, the access control logic does not properly validate whether the requesting user has sufficient permissions for the target private project, allowing the metadata to be returned. The vulnerability is exploitable over the network with low privileges and no user interaction required, making it straightforward to trigger for any authenticated GitLab EE user. The issue was originally reported via HackerOne (report #3615282) (GitHub Advisory, GitLab Patch Release).
Successful exploitation allows a low-privilege authenticated user to read work item metadata (such as issue titles, labels, assignees, milestones, or other project management data) from private GitLab EE projects to which they have no authorized access. The impact is limited to confidentiality — there is no integrity or availability impact — but exposure of private project metadata could reveal sensitive business information, internal project structure, or personnel assignments. This vulnerability does not enable code execution, lateral movement, or data modification (GitHub Advisory).
/api/v4/projects/:id/issues, /api/v4/projects/:id/work_items, or GraphQL endpoints for private project IDs from accounts with no project membership.GitLab has released patched versions addressing this vulnerability: 18.11.7, 19.0.4, and 19.1.2. Administrators should upgrade their GitLab EE installations to the appropriate fixed version as soon as possible. No configuration-based workaround has been published; upgrading is the only recommended remediation (GitLab Patch Release, GitHub Advisory).
The vulnerability was covered by several cybersecurity news outlets as part of GitLab's broader July 2026 patch release, which addressed eight security vulnerabilities across Community and Enterprise Editions. Coverage highlighted the patch release as a proactive security update rather than a response to active exploitation. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-8472 has been identified beyond standard patch reporting (GitLab Patch Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."