Description
Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized Service Account Creation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from insufficient validation of job submissions for service accounts in Jacamar CI versions prior to 0.30.0. Authenticated CI users can inject arbitrary service account names into job configurations. This lack of validation effectively allows an attacker to bypass authentication controls and create or impersonate service accounts that are normally granted higher privileges within the CI environment. The weakness is classified as improper enforcement of authentication, corresponding to CWE‑290.

Affected Systems

Jacamar CI deployments running any version earlier than 0.30.0 are affected when they run against GitLab Server versions 13.11 or newer, or when used with GitLab Server 13.10 with the allow_projects_to_create_service_accounts flag enabled. Later releases of either Jacamar CI or GitLab Server that do not expose the vulnerable configuration path are not affected.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability with significant impact on confidentiality and integrity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, but the required attacker credential is a legitimate CI user, which exists in many enterprises. The likely attack vector therefore involves an authenticated CI user who can trigger a job and supply arbitrary service account names, enabling unauthorized creation of privileged accounts. Security teams should treat this as a high‑risk vulnerability requiring urgent remediation.

Generated by OpenCVE AI on October 8, 2026 at 17:58 UTC.

Remediation

Vendor Solution

This issue presents a serious risk to all versions of Jacamar CI prior to v0.30.0 when used with GitLab Server v13.11 or later, or with v13.10 when the `allow_projects_to_create_service_accounts` feature flag enabled. If you are unable to immediately upgrade to the latest release, you can mitigate the risk by restricting the allowed accounts or groups in the configuration, or by using the RunAs validation script to check for bot accounts. Please see the release notes for a complete example.


OpenCVE Recommended Actions

  • Upgrade Jacamar CI to version 0.30.0 or later.
  • Restrict the allowed accounts or groups in the Jacamar CI configuration to limit service account creation.
  • Run the RunAs validation script to verify bot accounts and prevent spoofing.

Generated by OpenCVE AI on October 8, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Description Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.
Title Authentication Bypass by Spoofing in Jacamar CI
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T19:14:14.226Z

Reserved: 2026-10-08T11:33:21.365Z

Link: CVE-2026-107589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T15:17:45.153

Modified: 2026-10-08T15:17:45.153

Link: CVE-2026-107589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:00:18Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing