Missing Authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-8937
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to read private child issue contents from projects they cannot access.
The vulnerability exists due to missing authorization checks in the Epic Issues REST API when accessing linked work items within visible epics. A remote user can access linked work items within visible epics to read private child issue contents from projects they cannot access.
Disclosed content includes issue titles and descriptions.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-8937
Gitlab Community Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1