GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: developer-role user can influence the execution environment of Pipeline Execution Policy jobs

CVE-2026-15387Control plane, storage & DevOpscurated

Impact

Pipeline Execution Policies are how a platform team forces security and compliance jobs into pipelines it does not own. Improper handling of job dependencies lets a user holding only developer role shape the environment those enforcement jobs run in, weakening a control that is meant to sit outside the reach of project members. For a shop that builds container images and model artifacts in GitLab CI, that is an integrity gap in the pipeline producing what gets shipped to the GPU fleet. GitLab records low integrity impact and no confidentiality or availability impact, and says exploitation only works under certain conditions.

Who can reach it

An authenticated GitLab user with developer-role permissions on an affected project. No administrator access needed; no unauthenticated path.

What to do

Upgrade to GitLab EE 19.1.7, 19.2.5, or 19.3.1. On self-managed instances that is a package upgrade and a service restart of the GitLab application; nothing changes on the GPU nodes or the runners themselves.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.