MEDIUM
Missing Authorization in GitLab
Published Sep 29, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.26%
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.
Affected products
-
Affected
- ≥ 19.0, < 19.2.7
- ≥ 19.3, < 19.3.3
- ≥ 19.4, < 19.4.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above.
Weaknesses (1)
References (4)
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88689 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/600533
- https://hackerone.com/reports/3702369 technical-descriptionexploitpermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88689 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/work_items/600533 | ||
| https://hackerone.com/reports/3702369 | technical-descriptionexploitpermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved May 19, 2026
Link CVE-2026-8937
CISA Vulnrichment
Updated Sep 29, 2026
Red Hat
No data
GitHub
No data