Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.
Published: 2026-08-12
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in GitLab’s pipeline reference validation that allows an authenticated user with developer‑level permissions to execute CI/CD pipelines on a protected branch, even though the user does not have the required push rights. This improper authorization means an attacker can run arbitrary code on a protected code base, potentially leading to code injection, data exfiltration, or further lateral movement in the system. The weakness is identified as CWE‑863, which relates to missing or incorrect authorization checks.

Affected Systems

GitLab CE/EE, all releases from 19.0 up to but not including 19.0.6, from 19.1 up to but not including 19.1.4, and from 19.2 up to but not including 19.2.2. The affected product is the standard GitLab repository and CI/CD platform.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits to date. Because the attack requires an authenticated user with at least developer role, the likely vector is an insider or compromised account. The privilege escalation could be achieved by simply forming a pipeline trigger URL or API call that targets a protected branch without including push permissions. Given the absence of a public exploit, the probability of immediate exploitation remains uncertain, but the impact remains potentially catastrophic if an attacker gains sufficient access.

Generated by OpenCVE AI on August 12, 2026 at 23:55 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.0.6, 19.1.4, 19.2.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to version 19.0.6, 19.1.4, 19.2.2 or any later release that includes the pipeline validation fix.
  • Re‑evaluate the developer role and remove permissions that allow pipeline execution on protected branches when push rights are absent.
  • Continuously monitor CI/CD logs for unexpected pipeline triggers and restrict access to protected branches to only those users who explicitly need push rights.

Generated by OpenCVE AI on August 12, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-13T14:57:10.045Z

Reserved: 2026-07-10T15:40:05.160Z

Link: CVE-2026-15423

cve-icon Vulnrichment

Updated: 2026-08-13T14:57:06.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T18:17:23.820

Modified: 2026-08-19T16:44:22.503

Link: CVE-2026-15423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:00:09Z

Weaknesses