CVE-2026-8937: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.2.7 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.3.3 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.4.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated GitLab user may be able to read titles and descriptions of private child issues in projects they cannot access, when the affected work items are linked within epics visible to that user.
What information could be exposed?
The issue could expose private child issue contents, including issue titles and descriptions. The provided data does not indicate exposure of issue modification capabilities or availability impact.
Which releases need remediation?
Affected releases are GitLab CE/EE versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. Upgrade to 19.2.7, 19.3.3, 19.4.1, or a later version as applicable.