Improper Authorization in GitLab EE Affects Multiple Versions
CVE-2026-16794
4.3MEDIUM
What is CVE-2026-16794?
GitLab EE has identified a vulnerability due to inadequate authorization controls, permitting an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access sensitive protected variables in group projects. This issue was found in versions prior to 19.1.8, 19.2.6, and 19.3.2, highlighting the need for immediate patching to prevent unauthorized access and potential exploitation of the compliance framework management features.
Affected Version(s)
GitLab 18.11 < 19.1.8
GitLab 19.2 < 19.2.6
GitLab 19.3 < 19.3.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [manual_mint](https://hackerone.com/manual_mint) for reporting this vulnerability through our HackerOne bug bounty program