CVE-2026-8937

gitlab: Missing Authorization (CVE-2026-8937)

mediumEPSS 0.3%

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamigitlab
19.0.019.3.019.4.0

Metrics

4.3
Source: cna-v3
16.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-06 12:10 UTC
CWE-862

Weakness classes (CWE)

  • CWE-862Class

    Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-10-05 17:05 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.3 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.3 *cpe:2.3:a:gitlab:gitlab:19.4.0:*:*:*:community:*:*:* *cpe:2.3:a:gitlab:gitlab:19.4.0:*:*:*:enterprise:*:*:* *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.0.0 up to (excluding) 19.2.7 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.0.0 up to (excluding) 19.2.7
    • Reference Type: GitLab Inc.: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ Types: Release Notes, Vendor Advisory
    • Reference Type: GitLab Inc.: https://gitlab.com/gitlab-org/gitlab/-/work_items/600533 Types: Broken Link
    • Reference Type: GitLab Inc.: https://hackerone.com/reports/3702369 Types: Permissions Required
  2. CVE Modified2026-09-29 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-8937","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
  3. New CVE Received2026-09-29 10:17 UTC· cve@gitlab.com
    • Description: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
    • CWE: CWE-862
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/8xxx/CVE-2026-8937.json">CVE-2026-8937</a>