Authorization Flaw in GitLab EE Exposes CI/CD Variable Values
CVE-2026-92470
7.7HIGH
What is CVE-2026-92470?
A security flaw in GitLab EE has been identified, allowing authenticated users to potentially access sensitive Continuous Integration/Continuous Deployment (CI/CD) variable values. This vulnerability arises in specific versions of GitLab, where missing authorization checks permit access to debug-mode job traces via the Duo AI troubleshooting feature. The issue affects all versions from 18.7 prior to 19.2.7, 19.3 prior to 19.3.3, and 19.4 prior to 19.4.1. It is crucial for users to upgrade to the latest versions to mitigate potential risks to sensitive data.
Affected Version(s)
GitLab 18.7 < 19.2.7
GitLab 19.3 < 19.3.3
GitLab 19.4 < 19.4.1
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member Daniel Prause