GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: linked work items in a visible epic expose private issue titles and descriptions

CVSS 4.3CVE-2026-8937Control plane, storage & DevOpscurated

Impact

Authorization checks are missing on linked work items reachable through an epic the user can see, so an authenticated user can read child issue titles and descriptions from projects they have no access to. On a shared GitLab instance running a datacenter's build and deployment pipelines, that leaks the content of private planning and incident issues across project boundaries - including whatever infrastructure detail happens to be written in them. Read-only disclosure; separate from the security-policy authorization bug fixed in the same patch release, with a different code path and affected version range.

Who can reach it

Any authenticated GitLab user who can view an epic that links the private child issues. No elevated role needed.

What to do

Upgrade to GitLab 19.2.7, 19.3.3, or 19.4.1; versions from 19.0 before those are affected, CE and EE alike. Normal GitLab patch upgrade and service restart - no node drain or reboot.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.