Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Leaked GitLab Issue Email Address Enables Unauthorized Code Pushes and CI Execution

A private GitLab email‑to‑issue address was exposed, allowing anyone to commit patches, push to protected branches, and start CI pipelines as the targeted user. This underscores the need for robust access‑control monitoring and audit evidence in continuous‑control‑assurance programs.

Verisq™ Intelligence · 📅 September 24, 2026 · 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Leaked GitLab Issue Email Address Enables Unauthorized Code Pushes and CI Execution

What Happened — A private “email‑to‑issue” address that GitLab provides to each user was exposed. Anyone who obtains this address can email a patch that GitLab automatically commits on the user’s behalf, push to any branch the user can access (including main), and trigger CI/CD pipelines that run with the user’s permissions.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of treating an email address as a credential; a continuous‑control‑assurance program should require strong authentication and strict segregation of privileged actions.
  • Highlights the need for real‑time monitoring of code‑push events and CI job launches to provide a defensible audit trail.
  • Shows why automated evidence collection around access‑control policies is essential for audit readiness.

Who Is Affected – SaaS and DevOps platforms, their enterprise customers, and any organization that enables “email‑to‑issue” functionality.

Recommended Actions

  • Disable the “email work item to this project” feature or rotate the address immediately.
  • Enforce MFA and least‑privilege policies for all GitLab users.
  • Implement continuous logging of push events and CI job starts, and integrate them with a SIEM for real‑time alerts.
  • Review audit logs for any unauthorized commits made since the address was leaked.

Source: The Hacker News

Technical Notes – The attack vector is a stolen credential (the unique issue‑email address). No CVE is associated; the vulnerability lies in the design that treats the address as an authentication token. Exploited actions include code commit, branch push, and CI job execution under the compromised user’s identity. Source: same as above

📰 Original Source
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →