Sceawere

Vulnerability Detail

CVE-2026-8937UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GitLab Unauthorized Work Item Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
15h ago
Vendor
GitLab
Product
GitLab
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-29T10:17:13.540Z",
  "pubdate": "2026-09-29T10:17:13.540Z",
  "executiveSummary": "This vulnerability is an Improper Authorization flaw identified in GitLab CE/EE that allows authenticated users to gain unauthorized access to private child issue contents, including sensitive metadata such as titles and descriptions.\nThe issue stems from insufficient access control validation when traversing linked work items associated with epics that are otherwise visible to the user.\nAffected versions include GitLab CE/EE 19.0 prior to 19.2.7, 19.3 prior to 19.3.3, and 19.4 prior to 19.4.1.\nThe impact is a breach of confidentiality, as unauthorized users can retrieve information regarding private project tasks from projects for which they lack explicit access permissions.\nExploitation requires an authenticated user account and the ability to interact with epic objects that contain links to restricted work items.\nThe risk is categorized as significant, as it facilitates the leakage of potentially sensitive internal development information via legitimate platform features.",
  "technicalDetails": "The vulnerability resides within the authorization logic governing the interaction between Epic objects and their linked Work Items in the GitLab CE/EE codebase. Specifically, the backend fails to perform secondary access control checks (authorization gates) when an authenticated user requests details for work items associated with a visible parent Epic.\nThe root cause is a failure to enforce the principle of least privilege during the resolution of linked work items. When an Epic is visible to an authenticated user—either through public access or authorized private group membership—the application logic permits the retrieval of linked resource data without verifying if the user also possesses the requisite project-level permissions to view the target child issues.\nThe attack flow proceeds as follows: An authenticated attacker identifies or gains access to a parent Epic that they are permitted to view. The attacker then interacts with the API or internal object relationship endpoints responsible for enumerating 'linked work items' or 'child issues' associated with that Epic. Because the authorization check is scope-limited to the parent container (the Epic) rather than the individual child objects (the Work Items), the application backend incorrectly treats the sub-resources as accessible.\nConsequently, the server processes the request and returns the serialized JSON payload containing the sensitive contents of the private issues—specifically the titles and descriptions—despite the attacker lacking a direct relationship with the underlying project. This allows for the systematic enumeration and harvesting of internal project documentation and task details.\nAffected versions include all instances within the 19.0.x branch before 19.2.7, the 19.3.x branch before 19.3.3, and the 19.4.x branch before 19.4.1. The vulnerability is restricted to authenticated sessions and does not require elevated administrative privileges, but it does require that the attacker can view at least one legitimate parent Epic container. The impact post-exploitation involves the unauthorized disclosure of project-specific intellectual property and security-sensitive task information, potentially exposing internal development timelines, technical debt, or architectural vulnerabilities discussed in private issue threads."
}
CVE-2026-8937: GitLab Unauthorized Work Item Disclosure (MEDIUM Severity, CVSS: 4.3) | Sceawere