CVE-2026-12436: Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12436?
The severity of CVE-2026-12436 is high, with a score of 8.4 according to CVSS.
How do I fix CVE-2026-12436?
To fix CVE-2026-12436, upgrade GitLab to the latest version that includes the remediation, specifically version 19.0.5 or later.
What software is affected by CVE-2026-12436?
CVE-2026-12436 affects all versions of GitLab CE/EE from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1.
What type of vulnerability is CVE-2026-12436?
CVE-2026-12436 is categorized as an improperly controlled modification of dynamically-determined object attributes vulnerability.
What could be the impact of CVE-2026-12436?
The impact of CVE-2026-12436 could allow an authenticated user to modify CI/CD configurations belonging to another user, leading to unauthorized changes.