Description
GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope validation.
Published: 2026-09-16
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Exposure of Protected CI/CD Variables
Action: Patch Immediately
AI Analysis

Impact

GitLab Enterprise Edition contained a logic flaw (CWE-863) that could allow an authenticated user and, during its execution, read protected CI/CD variables that were intended to be visible only to higher‑privileged roles. The underlying problem was insufficient scope validation when accessing those variables.

Affected Systems

All GitLab Enterprise Edition releases in the 19.0, 19.2, and 19.3 series are affected. Specifically, any 19.0 release before 19.1.8, any 19.2 release before 19.2.6, and any 19.3 release before 19.3.2 are vulnerable. The issue applies to users who hold a developer role within that group.

Risk and Exploitability

The CVSS base score of 8.5 classifies this flaw as high risk, while the EPSS score of < 1% indicates a very low probability of exploitation at present. Based on the description, the likely attack vector is authenticated access within an organization’s internal network. If an attacker can trigger a policy test pipeline, they can read protected CI/CD variables that are intended for higher‑privileged roles. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 16, 2026 at 17:33 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab Enterprise Edition to at least 19.1.8, 19.2.6, or 19.3.2 (or a newer major release) to apply the official fix.
  • If an upgrade cannot be performed immediately, disable policy test pipelines globally or for the affected projects to prevent developers from executing them and exposing protected variables.
  • Alternatively, tighten developer role permissions or configure protected variables to be masked and only exposed to users with higher‑privileged roles.

Generated by OpenCVE AI on September 16, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope validation.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-16T15:39:28.393Z

Reserved: 2026-08-25T13:07:03.737Z

Link: CVE-2026-79708

cve-icon Vulnrichment

Updated: 2026-09-16T15:38:44.871Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T07:16:37.440

Modified: 2026-09-16T19:23:34.623

Link: CVE-2026-79708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T17:45:17Z

Weaknesses