CVE-2026-76910: Unleash: Clone-feature lets a user copy a feature from a project they cannot read
The clone-feature endpoint supports copying features across projects, but it does not verify that the caller can access the source project. A user with create permissions in one project can clone a feature from another project they cannot read and then inspect the copied configuration.
This vulnerability cannot be confirmed without Enterprise access. Report is based on a circumstantial evidence in the open-source repository.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-76910 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →