Database/Control plane, storage & DevOps
GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobs
Impact
Pipeline Execution Policies are how a platform team forces security and compliance jobs into pipelines it does not own. Improper handling of job dependencies lets a user holding only developer role shape the environment those enforcement jobs run in, weakening a control that is meant to sit outside the reach of project members. For a shop that builds container images and model artifacts in GitLab CI, that is an integrity gap in the pipeline producing what gets shipped to the GPU fleet. GitLab records low integrity impact and no confidentiality or availability impact, and says exploitation only works under certain conditions.
Who can reach it
An authenticated GitLab user with developer-role permissions on an affected project. No administrator access needed; no unauthenticated path.
What to do
Upgrade to GitLab EE 19.1.7, 19.2.5, or 19.3.1. On self-managed instances that is a package upgrade and a service restart of the GitLab application; nothing changes on the GPU nodes or the runners themselves.
References
Related entries
- GitLab EE: authenticated user can view restricted group configuration settingsCVE-2026-18244 · GitLab EE (group settings page authorization)Medium
- GitLab EE: GraphQL query exposes policy configuration from an unauthorized namespaceCVE-2026-18433 · GitLab EE (GraphQL query for namespace policy configuration)Medium
- NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have noCVE-2026-22052 · NetApp ONTAP S3 NAS bucket directory listingMedium
- GitLab EE: developer-role user can read external status check configuration for a merge requestCVE-2026-4879 · GitLab EE (merge request external status check API)Medium
- Jenkins: post-login redirect accepts URLs with tab or newline between slashes, enabling phishingCVE-2026-53437 · Jenkins core (post-login redirect URL validation)Medium
- GitLab EE: authenticated user bypasses IP access restrictions to read private merge request dataCVE-2026-6821 · GitLab EE (merge requests API, IP-based access restrictions)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.