Junglewise Threat Intelligence

CVE-2026-8144: GitLab CE/EE information disclosure in private group membership

CVE-2026-8144 · Severity: medium · CVSS 4.3 · Published 2026-05-14

Technologies: GitLab. Vendors: GitLab.

Executive brief

GitLab, a platform used for software development and version control, has addressed a security flaw that allowed certain users to see information they shouldn't have access to. Specifically, an authorized user who is a member of a project could discover the identities of members in private groups. While this does not allow for data destruction or system takeover, it results in a loss of privacy for group memberships that were intended to be hidden.

Technical details

A missing authorization check (CWE-862) in GitLab CE/EE allows an authenticated user with project-level membership to enumerate members of private groups. The vulnerability affects multiple version branches including 15.1 through 18.11. An attacker must have network access and valid credentials with at least project-level permissions to exploit this flaw. Successful exploitation results in the disclosure of private group membership information, which should otherwise be restricted. GitLab has released patches in versions 18.9.7, 18.10.6, and 18.11.3 to remediate this issue.

Affected products

  • GitLab GitLab CE/EE 15.1 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3
  • 2026-05-14: disclosed: Public disclosure of CVE-2026-8144

References

Related threats