GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variables

CVSS 4.3CVE-2026-16794Control plane, storage & DevOpscurated

Impact

Authorization on compliance framework management was too loose, letting a user with the Security Manager role execute arbitrary CI/CD jobs in group projects and reach protected CI variables. Protected variables are where operators keep registry credentials, kubeconfigs and cloud keys, so a role that was meant to be read-mostly and audit-oriented becomes a way to run code on shared runners and harvest the secrets that deploy to the cluster. On a GPU fleet those runners frequently have privileged access to node images and Kubernetes control planes. Requires an existing account with that role.

Who can reach it

An authenticated GitLab EE user holding the Security Manager role in the group, over the network to the GitLab instance.

What to do

Upgrade self-managed GitLab EE to 19.1.8, 19.2.6, or 19.3.2 (affected from 18.11). Package upgrade and service restart. Because protected variables may have been exposed, rotate any CI secrets reachable by Security Manager users on instances that ran an affected version with that role assigned.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.