Sceawere
Vulnerability Detail
CVE-2026-4523UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthorized GraphQL CI Trace Access
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 15h ago
- Vendor
- GitLab
- Product
- GitLab
- Attack Type
- CWE-862: Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-09-29T10:17:11.613Z",
"pubdate": "2026-09-29T10:17:11.613Z",
"executiveSummary": "A critical authorization vulnerability exists within the GitLab CE/EE GraphQL API, allowing unauthenticated remote attackers to exfiltrate sensitive CI/CD job trace contents.\nThe vulnerability stems from improper authorization enforcement when querying job traces, specifically exposing sensitive environment variables embedded within the output logs.\nAffected versions include all instances from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.\nThe primary risk implication is the potential for full compromise of CI/CD pipelines, as exposed sensitive variables often include authentication tokens, API keys, and deployment credentials.\nExploitation does not require prior authentication, making this an externally accessible flaw if the GitLab instance is exposed to the network.\nAttackers can leverage the GraphQL endpoint to perform targeted queries against specific job IDs to extract trace data, bypassing the standard permission checks intended to protect build output privacy.",
"technicalDetails": "The vulnerability is located within the GitLab GraphQL API implementation responsible for retrieving CI/CD job traces. The root cause is an improper authorization check that fails to validate the requestor's identity or access rights when querying specific trace data structures via GraphQL.\nTypically, GitLab enforces strict visibility rules for CI/CD artifacts and logs, ensuring only authorized project members or runners can access sensitive data. In the vulnerable versions, the GraphQL resolver logic incorrectly permits unauthenticated access to the trace contents if specific criteria are met by the query structure.\nThe attack flow involves an attacker crafting a malicious GraphQL query targeting the 'job' object, specifically requesting the 'trace' field or related log output. Because the underlying authorization middleware fails to verify the context of the user—or lacks the correct permission check for anonymous sessions—the API returns the raw content of the job trace.\nSensitive variables are frequently masked in the UI but often present in the backend trace data for debugging purposes. An attacker can leverage this unauthorized access to retrieve these raw logs, effectively bypassing the mask-and-filter logic applied to the standard GitLab interface. By targeting specific project and job IDs, an attacker can harvest high-privilege credentials that are dynamically injected into the CI environment as masked variables.\nAffected versions span a significant range: 15.11.x through 19.2.6, 19.3.0 through 19.3.2, and 19.4.0. The vulnerability is network-accessible and requires no privilege escalation or user interaction once the target job ID is identified. Post-exploitation impact includes unauthorized credential theft, pipeline manipulation, and potential lateral movement into integrated cloud or infrastructure environments using the stolen secrets found within the job traces."
}