Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to CI/CD variables
Action: Patch
AI Analysis

Impact

GitLab Community and Enterprise Editions use an environment scope pattern matcher that, due to improper input validation, can allow an authenticated user to view CI/CD variables that are scoped to a different environment. The flaw permits the attacker to read secrets normally restricted to a specific environment, potentially exposing credentials, tokens, or other confidential data. This issue corresponds to the CWE‑863 "Improper Authorization" weakness.

Affected Systems

Affected systems include all GitLab Community Edition and Enterprise Edition releases starting with version 15.7 and up through the latest releases; unpatched versions less than 19.1.8, less than 19.2.6, or less than 19.3.2 are vulnerable. Users running those versions are susceptible to the vulnerability.

Risk and Exploitability

The CVSS score of 7.7 classifies this flaw as high severity. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that active exploitation is not currently known. The likely attack vector requires a valid authenticated account to supply a crafted environment scope pattern. Once authenticated, the attacker can read variables that should belong to another environment, giving them the ability to compromise downstream deployments or expose secrets to unprivileged users.

Generated by OpenCVE AI on September 20, 2026 at 14:48 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to at least 19.1.8, 19.2.6, or 19.3.2 (or later).
  • Regenerate any CI/CD variables that may have been exposed from earlier configurations to eliminate retained secrets.
  • Restrict pipeline and variable access permissions to the minimum users that truly need them.
  • Audit existing environment scope definitions and tighten patterns to prevent overly permissive matches.

Generated by OpenCVE AI on September 20, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Sun, 20 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-20T00:45:43.263Z

Reserved: 2026-06-24T15:06:08.048Z

Link: CVE-2026-13210

cve-icon Vulnrichment

Updated: 2026-09-20T00:42:11.175Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:17:16.280

Modified: 2026-09-28T20:04:00.453

Link: CVE-2026-13210

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses