CVE-2026-15387

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.
References
Link Resource
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ Release Notes Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/work_items/605632 Issue Tracking Vendor Advisory
https://hackerone.com/reports/3754358 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2026-08-26 14:17

Updated : 2026-08-31 15:41


NVD link : CVE-2026-15387

Mitre link : CVE-2026-15387

CVE.ORG link : CVE-2026-15387


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-349

Acceptance of Extraneous Untrusted Data With Trusted Data