Sceawere

Vulnerability Detail

CVE-2026-4523UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthorized GraphQL CI Trace Access

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
15h ago
Vendor
GitLab
Product
GitLab
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-09-29T10:17:11.613Z",
  "pubdate": "2026-09-29T10:17:11.613Z",
  "executiveSummary": "A critical authorization vulnerability exists within the GitLab CE/EE GraphQL API, allowing unauthenticated remote attackers to exfiltrate sensitive CI/CD job trace contents.\nThe vulnerability stems from improper authorization enforcement when querying job traces, specifically exposing sensitive environment variables embedded within the output logs.\nAffected versions include all instances from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.\nThe primary risk implication is the potential for full compromise of CI/CD pipelines, as exposed sensitive variables often include authentication tokens, API keys, and deployment credentials.\nExploitation does not require prior authentication, making this an externally accessible flaw if the GitLab instance is exposed to the network.\nAttackers can leverage the GraphQL endpoint to perform targeted queries against specific job IDs to extract trace data, bypassing the standard permission checks intended to protect build output privacy.",
  "technicalDetails": "The vulnerability is located within the GitLab GraphQL API implementation responsible for retrieving CI/CD job traces. The root cause is an improper authorization check that fails to validate the requestor's identity or access rights when querying specific trace data structures via GraphQL.\nTypically, GitLab enforces strict visibility rules for CI/CD artifacts and logs, ensuring only authorized project members or runners can access sensitive data. In the vulnerable versions, the GraphQL resolver logic incorrectly permits unauthenticated access to the trace contents if specific criteria are met by the query structure.\nThe attack flow involves an attacker crafting a malicious GraphQL query targeting the 'job' object, specifically requesting the 'trace' field or related log output. Because the underlying authorization middleware fails to verify the context of the user—or lacks the correct permission check for anonymous sessions—the API returns the raw content of the job trace.\nSensitive variables are frequently masked in the UI but often present in the backend trace data for debugging purposes. An attacker can leverage this unauthorized access to retrieve these raw logs, effectively bypassing the mask-and-filter logic applied to the standard GitLab interface. By targeting specific project and job IDs, an attacker can harvest high-privilege credentials that are dynamically injected into the CI environment as masked variables.\nAffected versions span a significant range: 15.11.x through 19.2.6, 19.3.0 through 19.3.2, and 19.4.0. The vulnerability is network-accessible and requires no privilege escalation or user interaction once the target job ID is identified. Post-exploitation impact includes unauthorized credential theft, pipeline manipulation, and potential lateral movement into integrated cloud or infrastructure environments using the stolen secrets found within the job traces."
}
CVE-2026-4523: Unauthorized GraphQL CI Trace Access (LOW Severity, CVSS: 3.7) | Sceawere