CVE-2026-4523
Received Received - Intake

Unauthenticated CI/CD Job Trace Exposure in GitLab

Vulnerability report for CVE-2026-4523, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitLab Inc.

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 10 associated CPEs
Vendor Product Version / Range
gitlab gitlab_ce From 15.11 (inc) to 19.2.7 (exc)
gitlab gitlab_ee From 15.11 (inc) to 19.2.7 (exc)
gitlab gitlab_ce From 19.3.0 (inc) to 19.3.3 (exc)
gitlab gitlab_ee From 19.3.0 (inc) to 19.3.3 (exc)
gitlab gitlab_ce From 19.4.0 (inc) to 19.4.1 (exc)
gitlab gitlab_ee From 19.4.0 (inc) to 19.4.1 (exc)
gitlab gitlab_ce From 19.2.0 (inc) to 19.3.3 (exc)
gitlab gitlab_ee From 19.2.0 (inc) to 19.3.3 (exc)
gitlab gitlab_ce From 19.3.0 (inc) to 19.4.1 (exc)
gitlab gitlab_ee From 19.3.0 (inc) to 19.4.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in GitLab CE/EE allowed an unauthenticated user to read CI/CD job trace contents containing sensitive variable values due to improper authorization enforcement in the GraphQL API. It affects versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1.

Detection Guidance

To detect this vulnerability, check if your GitLab instance is running a vulnerable version (15.11 before 19.2.7, 19.3 before 19.3.3, or 19.4 before 19.4.1). Verify the GraphQL API for unauthorized access to CI/CD job traces. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to access sensitive data like environment variables or secrets exposed in CI/CD job traces, potentially leading to unauthorized access or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive CI/CD job trace contents, including confidential variable values. This may violate data protection requirements under GDPR (e.g., Article 32 on security of processing) and HIPAA (e.g., safeguards for protected health information) by exposing personal or sensitive data without proper authorization.

Mitigation Strategies

Upgrade GitLab to a patched version (19.2.7, 19.3.3, or 19.4.1 or later) immediately. Review and restrict GraphQL API access to prevent unauthorized data exposure. Monitor for suspicious activity in CI/CD job traces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4523. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart