chiprook
← Security
SecuritySeptember 25, 2026, 21:58

Aikido: GitLab's secret issue email grants account-wide access

Aikido Security found that GitLab's secret email address for creating issues embeds a single account-wide PAT prefixed with "glimt-". Anyone who knows the address can create issues and merge requests, push code and run CI/CD jobs across the account's projects, bypassing IP restrictions. GitLab calls the behavior intended and offers no way to disable the feature.

Aikido: GitLab's secret issue email grants account-wide access
#GitLab
Read next
Security

Leaked GitLab issue email address lets anyone push code and run CI jobs as you

Gadgets

Dyson reveals design secrets of CameraJet toothbrush, explains early issues

Security

ConfigConfusion: one Kubernetes YAML grants GCP organization owner rights

Security

Sizing Self-Managed GitLab Exposure After CVE-2026-85706