Authorization Flaw in GitLab EE Exposes CI/CD Variable Values
CVE-2026-92470

7.7HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-92470?

A security flaw in GitLab EE has been identified, allowing authenticated users to potentially access sensitive Continuous Integration/Continuous Deployment (CI/CD) variable values. This vulnerability arises in specific versions of GitLab, where missing authorization checks permit access to debug-mode job traces via the Duo AI troubleshooting feature. The issue affects all versions from 18.7 prior to 19.2.7, 19.3 prior to 19.3.3, and 19.4 prior to 19.4.1. It is crucial for users to upgrade to the latest versions to mitigate potential risks to sensitive data.

Affected Version(s)

GitLab 18.7 < 19.2.7

GitLab 19.3 < 19.3.3

GitLab 19.4 < 19.4.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member Daniel Prause
.