Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables within group projects due to improper authorization controls on compliance framework management.
Published: 2026-09-16
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to CI/CD jobs and protected variables
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper authorization check in GitLab Enterprise Edition that allows an authenticated user with the Security Manager role to trigger arbitrary CI/CD jobs and retrieve protected group variables. This flaw is formally classified as CWE‑862. The potential impact is that a user with legitimate credentials could execute arbitrary code on the CI runner and exfiltrate sensitive configuration data, effectively bypassing intended access controls. The flaw could also be used to compromise the integrity of build pipelines.

Affected Systems

Affected products are GitLab Enterprise Edition for all releases from 18.11 up to, but not including, 19.1.8, 19.2.6, and 19.3.2. Users running any of these product versions are susceptible until they apply the official patch. The CVE references indicate that the issue has been addressed in the 19.1.8, 19.2.6, and 19.3.2 releases and later.

Risk and Exploitability

The CVSS base score is 4.3, reflecting moderate severity. The EPSS score is below 1%, indicating a very low probability of exploitation in the wild. No entries exist in the CISA KEV catalog, and the exploit requires a valid authenticated session with a specific role; no public or remote exploitation method is known. Despite the low risk metrics, the ability to run arbitrary jobs remains a significant risk within a compromised internal environment; therefore the recommended response is to patch.

Generated by OpenCVE AI on September 16, 2026 at 15:24 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade to GitLab EE 19.1.8, 19.2.6, or 19.3.2 or later to remove the flaw.
  • Review and restrict the Security Manager role usage, limiting it to trusted administrators or removing the role if not needed.
  • Apply CI/CD configuration hardening, such as disabling the ability for privileged users to run arbitrary pipeline jobs or restrict variables access, and monitor for unexpected job execution activity.

Generated by OpenCVE AI on September 16, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables within group projects due to improper authorization controls on compliance framework management.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-16T15:43:11.880Z

Reserved: 2026-07-23T18:04:00.169Z

Link: CVE-2026-16794

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:40.168Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T07:16:32.807

Modified: 2026-09-16T19:23:34.623

Link: CVE-2026-16794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:30:11Z

Weaknesses