Intel

AIKIDO-2026-542928

gitlab-ce is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-79708 Published 3 days ago

85

High Risk

This Affects:

OSgitlab-ce
19.0.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

Scheduled Pipeline Execution Policy tests do not adequately validate scope before running. An authenticated Developer can execute a policy test pipeline on projects in their group and access protected CI/CD variables that should be limited to higher-privileged roles. The fix tightens scope validation for policy test pipelines so Developers cannot reach those protected variables.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use Pipeline Execution Policies with protected CI/CD variables.

Background info

gitlab-ce is vulnerable to Incorrect Authorization in versions 19.0.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform