{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T04:15:43.883","vulnerabilities":[{"cve":{"id":"CVE-2026-1080","sourceIdentifier":"cve@gitlab.com","published":"2026-02-11T12:16:04.120","lastModified":"2026-06-17T10:14:57.687","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to access iteration data from private descendant groups by querying the iterations API endpoint."},{"lang":"es","value":"GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 16.7 anterior a la 18.6.6, la 18.7 anterior a la 18.7.4, y la 18.8 anterior a la 18.8.4 que, bajo ciertas condiciones, podría haber permitido a un usuario autenticado acceder a datos de iteración de grupos descendientes privados al consultar el endpoint de la API de iteraciones."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"16.7","lessThan":"18.6.6","versionType":"semver","status":"affected"},{"version":"18.7","lessThan":"18.7.4","versionType":"semver","status":"affected"},{"version":"18.8","lessThan":"18.8.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-11T15:35:19.935747Z","id":"CVE-2026-1080","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.7.0","versionEndExcluding":"18.6.6","matchCriteriaId":"9C40909F-AEAD-4AC0-AD12-082D2E389042"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.7.0","versionEndExcluding":"18.7.4","matchCriteriaId":"DA7B13F4-05B9-436E-A1DC-6C65DB7B44FE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.8.0","versionEndExcluding":"18.8.4","matchCriteriaId":"6D01D64A-0619-427D-B351-4101FC257674"}]}]}],"references":[{"url":"https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","source":"cve@gitlab.com","tags":["Release Notes","Vendor Advisory"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/586477","source":"cve@gitlab.com","tags":["Broken Link","Issue Tracking"]},{"url":"https://hackerone.com/reports/3484568","source":"cve@gitlab.com","tags":["Permissions Required"]}]}}]}