Database/Control plane, storage & DevOps
GitLab EE: Security Manager role can run arbitrary CI/CD jobs and read protected variables
Impact
Authorization on compliance framework management was too loose, letting a user with the Security Manager role execute arbitrary CI/CD jobs in group projects and reach protected CI variables. Protected variables are where operators keep registry credentials, kubeconfigs and cloud keys, so a role that was meant to be read-mostly and audit-oriented becomes a way to run code on shared runners and harvest the secrets that deploy to the cluster. On a GPU fleet those runners frequently have privileged access to node images and Kubernetes control planes. Requires an existing account with that role.
Who can reach it
An authenticated GitLab EE user holding the Security Manager role in the group, over the network to the GitLab instance.
What to do
Upgrade self-managed GitLab EE to 19.1.8, 19.2.6, or 19.3.2 (affected from 18.11). Package upgrade and service restart. Because protected variables may have been exposed, rotate any CI secrets reachable by Security Manager users on instances that ran an affected version with that role assigned.
References
Related entries
- GitLab EE: authenticated user can view restricted group configuration settingsCVE-2026-18244 · GitLab EE (group settings page authorization)Medium
- GitLab EE: GraphQL query exposes policy configuration from an unauthorized namespaceCVE-2026-18433 · GitLab EE (GraphQL query for namespace policy configuration)Medium
- NetApp ONTAP S3 NAS bucket directory listing: An authenticated S3 user lists the contents of directories they have noCVE-2026-22052 · NetApp ONTAP S3 NAS bucket directory listingMedium
- GitLab EE: developer-role user can read external status check configuration for a merge requestCVE-2026-4879 · GitLab EE (merge request external status check API)Medium
- Jenkins: post-login redirect accepts URLs with tab or newline between slashes, enabling phishingCVE-2026-53437 · Jenkins core (post-login redirect URL validation)Medium
- GitLab EE: authenticated user bypasses IP access restrictions to read private merge request dataCVE-2026-6821 · GitLab EE (merge requests API, IP-based access restrictions)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.