Missing Authorization in GitLab Enterprise Edition - CVE-2026-92470
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to access sensitive CI/CD variable values from debug-mode job traces.
The vulnerability exists due to missing authorization checks in the Duo AI troubleshooting feature when accessing debug-mode job traces. A remote user can access debug-mode job traces to access sensitive CI/CD variable values from debug-mode job traces.