Description
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control due to improper authorization checks.
Published: 2026-09-23
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization bypass allows developers to override AI governance controls
Action: Patch
AI Analysis

Impact

GitLab Enterprise Edition versions earlier than 19.2.7, 19.3.3, or 19.4.1 contain an authorization flaw that enables users with developer role permissions to bypass administrator‑configured AI tool governance controls for workflows in namespaces they do not control; this allows developers to override governance restrictions that should prevent unsafe or inappropriate AI usage.

Affected Systems

Affected products are GitLab EE, all installations using GitLab 19.1 up to (but not including) 19.2.7, GitLab 19.3 up to (but not including) 19.3.3, and GitLab 19.4 up to (but not including) 19.4.1. The vulnerable logic applies to any instance of GitLab where the AI tool governance policies are enabled and developer users exist in namespaces without administrative ownership.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the lack of an EPSS score means current exploit probability is unknown; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated developer account and namespace context where governance controls are active; attackers do not need external access to reach the flaw, making it a localized privilege‑escalation scenario that could lead to policy circumvention.

Generated by OpenCVE AI on September 24, 2026 at 00:22 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab EE to version 19.2.7, 19.3.3, 19.4.1 or later to apply the official fix.
  • After upgrading, review that AI tool governance controls are correctly enforced for all namespaces by running a configuration audit of the AI governance settings.
  • If an upgrade is delayed, limit developer role permissions or remove AI tool governance features from critical namespaces until the patch is applied, and monitor for unauthorized AI workflow execution.

Generated by OpenCVE AI on September 24, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control due to improper authorization checks.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-23T23:05:00.130Z

Reserved: 2026-09-16T12:35:15.160Z

Link: CVE-2026-92529

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T00:17:22.323

Modified: 2026-09-24T00:17:22.323

Link: CVE-2026-92529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T00:30:07Z

Weaknesses