Sceawere

Vulnerability Detail

CVE-2026-10518UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GitLab Improper Authorization Policy Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
15h ago
Vendor
GitLab
Product
GitLab
Attack Type
CWE-863: Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with guest-level permissions to read private security policy content they were not authorized to access due to improper authorization enforcement.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-29T10:17:10.863Z",
  "pubdate": "2026-09-29T10:17:10.863Z",
  "executiveSummary": "This vulnerability is an improper authorization enforcement flaw within GitLab EE that allows authenticated users with guest-level permissions to bypass security controls and access private security policy configurations. The issue impacts specifically defined versions of GitLab EE, including 17.9 through 19.2.6, 19.3.0 through 19.3.2, and 19.4.0. By exploiting this authorization oversight, a malicious actor can gain unauthorized visibility into sensitive security policies that govern protected projects or namespaces. The risk is significant as it facilitates unauthorized reconnaissance of security postures, potentially exposing infrastructure configurations, compliance requirements, or vulnerability scanning rules that are intended to be restricted to administrative or security-authorized personnel. Successful exploitation requires an authenticated session with at least guest-level privileges, meaning the attack vector is restricted to internal users or accounts with minimal project access. The exposure of such metadata can be leveraged to craft more sophisticated targeted attacks against the CI/CD pipeline or identified target environments.",
  "technicalDetails": "The vulnerability resides in the authorization logic governing the retrieval of security policy data within GitLab EE. The root cause is a failure in the application’s backend access control mechanisms, which do not sufficiently validate the requester's authorization level before returning serialized security policy content. Under specific conditions, the authorization middleware fails to perform an adequate check against the requesting user's project permissions, effectively defaulting to an overly permissive state for policy-related API endpoints or data retrieval functions.\nThe attack flow begins with an authenticated user possessing guest-level access to a repository or namespace. The attacker interacts with the GitLab application interface or API endpoints responsible for querying security policy configurations. Because the application logic incorrectly confirms the user's eligibility to view these objects, the backend service processes the request and retrieves the requested security policies from the underlying data store. The server then transmits the sensitive policy content—which may include detailed scan settings, compliance rules, and security project associations—back to the guest user.\nThe exploitation does not require administrative rights, code injection, or elevated system privileges, as it relies on the application's failure to enforce existing organizational security boundaries. By repeatedly querying these endpoints, an attacker can enumerate the security policy landscape of the target instance, identifying gaps in vulnerability management or discovering hidden security configurations. The vulnerable component is the centralized security policy management engine within GitLab EE, which handles the definition, inheritance, and retrieval of security policies across the platform.\nThe scope of affected versions includes GitLab EE 17.9 through 19.2.6, 19.3.0 through 19.3.2, and 19.4.0. Post-exploitation, the impact is primarily centered on information disclosure. An attacker can leverage the obtained security policy information to bypass or circumvent specific scanning routines, gain insights into the organization's defensive strategy, or identify specific project weaknesses that are prioritized or ignored by the existing policy set. This breach of confidentiality allows for reconnaissance activities that compromise the integrity of the security-by-design principles implemented within the GitLab ecosystem."
}
CVE-2026-10518: GitLab Improper Authorization Policy Disclosure (MEDIUM Severity, CVSS: 4.3) | Sceawere