Junglewise Threat Intelligence

CVE-2026-8716: GitLab CE/EE information disclosure in CI data via incorrect ref resolution

CVE-2026-8716 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Technologies: GitLab CE, GitLab EE. Vendors: GitLab.

Executive brief

GitLab has fixed a security issue in its Community and Enterprise editions that could allow a logged-in user to access Continuous Integration (CI) data they were not intended to see. GitLab is a platform used by software teams to manage code and automate the building and testing of applications. If exploited, an attacker could view sensitive build information or pipeline data from different branches or reference types within the system.

Technical details

An information disclosure vulnerability exists in GitLab CE/EE versions 12.7 through 19.0.1 due to the use of an incorrectly-resolved name or reference (CWE-706). Under specific conditions, an authenticated attacker can bypass intended access controls to retrieve Continuous Integration (CI) data from a different 'ref' type than what was originally authorized. The vulnerability is reachable over the network with low privileges and requires no user interaction. GitLab has released patches in versions 18.10.7, 18.11.4, and 19.0.1 to address this issue.

Affected products

  • GitLab GitLab CE/EE 12.7 to 18.10.7, 18.11 to 18.11.4, 19.0 to 19.0.1

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: patched
  • 2026-05-27: advisory

References

Related threats