CVE-2026-15831

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:19.2.0:*:*:*:enterprise:*:*:*

History

No history.

Information

Published : 2026-07-29 20:17

Updated : 2026-08-03 12:59


NVD link : CVE-2026-15831

Mitre link : CVE-2026-15831

CVE.ORG link : CVE-2026-15831


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-1270

Generation of Incorrect Security Tokens