Missing Authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-8937

 

Missing Authorization in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-8937

Published: September 23, 2026


Vulnerability identifier: #VU151879
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8937
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read private child issue contents from projects they cannot access.

The vulnerability exists due to missing authorization checks in the Epic Issues REST API when accessing linked work items within visible epics. A remote user can access linked work items within visible epics to read private child issue contents from projects they cannot access.

Disclosed content includes issue titles and descriptions.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

How to mitigate CVE-2026-8937

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1
Gitlab Community Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1

External References

Related Security Bulletins