Improper Authorization Vulnerability in GitLab EE
CVE-2026-3035
5.5MEDIUM
What is CVE-2026-3035?
GitLab EE versions prior to 19.1.7, 19.2.5, and 19.3.1 contain an improper authorization vulnerability that may allow authenticated users with project Maintainer permissions to access the terminal of protected environments they are not authorized to use. This issue stems from insufficient authorization checks within the application, potentially exposing sensitive data and leading to unauthorized actions. GitLab has addressed this problem in the specified versions, reinforcing the importance of keeping software updated for optimal security.
Affected Version(s)
GitLab 11.3 < 19.1.7
GitLab 19.2 < 19.2.5
GitLab 19.3 < 19.3.1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [go7f0](https://hackerone.com/go7f0) for reporting this vulnerability through our HackerOne bug bounty program