Threat Advisory

GitLab Flaw Exposes Data Through Security Vulnerabilities

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in GitLab Community Edition (CE) and Enterprise Edition (EE), affecting versions prior to 19.2.1, 19.1.3, and 19.0.5. These flaws include information disclosure, improper authorization, access control bypass, denial of service (DoS), prompt injection, privilege escalation, and CI/CD pipeline manipulation vulnerabilities. Successful exploitation could allow attackers to access unauthorized information, bypass branch protection mechanisms, manipulate CI/CD workflows, disrupt GitLab services, or weaken security controls protecting source code and software development pipelines. GitLab strongly recommends upgrading affected self-managed installations to the latest patched releases immediately.

• CVE-2026-6267 – An insufficient access control vulnerability in GitLab Workhorse's internal request handling that could allow an authenticated user with the Developer role to access unauthorized information. (High – CVSS 8.5)[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in GitLab Community Edition (CE) and Enterprise Edition (EE), affecting versions prior to 19.2.1, 19.1.3, and 19.0.5. These flaws include information disclosure, improper authorization, access control bypass, denial of service (DoS), prompt injection, privilege escalation, and CI/CD pipeline manipulation vulnerabilities. Successful exploitation could allow attackers to access unauthorized information, bypass branch protection mechanisms, manipulate CI/CD workflows, disrupt GitLab services, or weaken security controls protecting source code and software development pipelines. GitLab strongly recommends upgrading affected self-managed installations to the latest patched releases immediately.

• CVE-2026-6267 – An insufficient access control vulnerability in GitLab Workhorse's internal request handling that could allow an authenticated user with the Developer role to access unauthorized information. (High – CVSS 8.5)[emaillocker id="1283"]

• CVE-2026-12436 – An improper validation vulnerability in the Pipeline Schedule API that could allow an authenticated attacker to modify another user's CI/CD pipeline schedule or configuration. (High – CVSS 8.4)

• CVE-2026-15975 – An insufficient resource throttling vulnerability in Merge Request Discussions that allows an unauthenticated attacker to trigger a denial-of-service (DoS) condition by exhausting server resources. (High – CVSS 7.5)

• CVE-2026-13113 – A race condition in Merge Request Approval Rules that could allow an authenticated user to merge code into protected branches without obtaining the required approvals.

• CVE-2026-6336 – A missing authorization check in Project Import Status that could allow an unauthorized user to view project import source information.

• CVE-2026-16553 – An information disclosure vulnerability affecting pipeline test reports that may expose sensitive information to unauthorized users.

• CVE-2026-15077 – A prompt injection vulnerability in GitLab Duo Code Review that could allow disclosure of information from unauthorized projects.

• CVE-2026-15831 – An improper security token generation vulnerability in GitLab Duo Workflows that could allow authenticated users to bypass administrator-configured governance policies.

• CVE-2026-14341 – An access control vulnerability that could result in unauthorized access to protected GitLab resources under specific conditions.

• CVE-2026-14351 – An authorization-related vulnerability that could expose confidential GitLab metadata or information to unauthorized users.

• CVE-2026-4672 – An authorization weakness that could impact GitLab security controls, potentially allowing unauthorized access to protected resources.

• CVE-2026-3093 – An access control vulnerability that could enable unauthorized actions under specific conditions within affected GitLab instances.

• CVE-2025-14562 – An improper authorization vulnerability in Merge Request Collaboration Settings that could allow a developer to continue committing changes to a project after their membership has been revoked.

These vulnerabilities present a significant risk to organizations relying on GitLab for source code management and CI/CD operations. Exploitation could lead to unauthorized data access, manipulation of software development pipelines, bypass of security controls, information disclosure, privilege escalation, and service disruption. Organizations should immediately upgrade to GitLab CE/EE 19.2.1, 19.1.3, or 19.0.5 (or later) and review access controls, pipeline configurations, and audit logs for signs of suspicious activity.

RECOMMENDATION:

We recommend you to update GitLab patch release 19.2.1 to versions 19.2.1, 19.1.3, or 19.0.5 depending on your installed branch.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu