Intel

AIKIDO-2026-594701

gitlab-ce is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-13210 Published Yesterday

77

High Risk

This Affects:

OSgitlab-ce
15.7.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

The CI/CD environment variable scope pattern matcher does not validate inputs correctly. An authenticated user can access CI/CD variables outside their intended environment scope. The fix validates environment scope patterns so variables cannot be matched outside the intended scope.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use environment-scoped CI/CD variables.

Background info

gitlab-ce is vulnerable to Incorrect Authorization in versions 15.7.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce and/or the gitlab-ee library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform