Database/Control plane, storage & DevOps
GitLab EE: pending members receive custom-role permissions before their membership is active
Impact
Incorrect privilege assignment does not account for membership state, so a user whose membership is still pending can receive the permissions granted by a custom role. On a self-managed GitLab that gates access to fleet CI/CD and artifact registries, that means the approval step operators rely on before granting access is not the point at which access actually starts. GitLab rates it 3.3 with high privileges and high attack complexity required, and describes low confidentiality and integrity impact - the granted permissions are whatever the custom role carries, which the record does not enumerate. Affects 15.6 before 19.0.6, 19.1 before 19.1.4 and 19.2 before 19.2.2.
Who can reach it
A user with a pending membership on a group or project where a custom role is assigned; exploitation additionally requires high privileges elsewhere in the instance per GitLab's scoring. Network access to the instance is required.
What to do
Upgrade to 19.0.6, 19.1.4 or 19.2.2 per the GitLab 19.2.2 patch release - a package upgrade and service restart (Omnibus reconfigure/restart or a Helm chart bump), no node drain. Afterwards, audit pending memberships attached to custom roles and confirm no access was exercised before approval.
References
Related entries
- Grafana: legacy correlation records can be read and permanently deleted across organizationsCVE-2026-21727 · Grafana (Correlations feature, legacy org_id = 0 records)Low
- RabbitMQ: Unsanitized username rendered in the management UICVE-2021-32718 · RabbitMQLow
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysCVE-2023-32082 · etcdLow
- Prometheus / Thanos (golang-jwt): Unclear ParseWithClaims error behaviorCVE-2024-51744 · Prometheus / Thanos (golang-jwt)Low
- GitLab: a developer removed from a project can still push commits via merge request collaboration settingsCVE-2025-14562 · GitLab CE/EE (merge request collaboration authorization)Low
- Inspektor Gadget: malformed ELF crashes or exhausts memory in the privileged eBPF tracerCVE-2026-44778 · Inspektor Gadget uprobetracer USDT note parser (pkg/uprobetracer/usdt.go)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.