CVE-2026-79708: Incorrect Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.1.8 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.2.6 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.3.2
Event History
Frequently Asked Questions
Which users could exploit this issue?
An authenticated user with Developer permissions could exploit it, provided the affected conditions for running a policy test pipeline on projects within their group were present.
What information could be exposed or changed?
The user could access protected CI/CD variables that were restricted to higher-privileged roles. The issue is also rated as having high integrity impact.
Which releases need remediation?
GitLab EE is affected from 19.0 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2. Upgrading to the applicable fixed release remediates the issue.