Database/Control plane, storage & DevOps
GitLab EE: project Maintainer can open a terminal on a protected environment they are not authorized for
Impact
Protected environments exist so that only a named set of users can touch production deployments; this bug lets any project Maintainer bypass that gate and open the environment's web terminal. On a fleet where GitLab drives model deployment, that terminal is an interactive shell inside the running deployment's container, with whatever service credentials and mounted volumes it holds. The scope is marked changed in the vendor's own scoring, meaning access reaches beyond the GitLab instance into the deployed workload. Anyone who has been given Maintainer on a project for ordinary reasons - CI configuration, runner registration - inherits access to environments the org deliberately restricted.
Who can reach it
An authenticated GitLab user holding project Maintainer permissions on an affected project. No administrator rights and no access to the environment itself are required.
What to do
Upgrade GitLab EE to 19.3.1, 19.2.5 or 19.1.7 depending on branch; GitLab.com is already patched. This is a package upgrade plus a restart of the GitLab services (Puma/Sidekiq) - no node drain or reboot. Until then, audit who holds Maintainer on projects that own protected environments and review terminal session logs for that period.
References
Related entries
- Linux EDAC/mc - error path ordering in edac_mc_alloc(): When a private-data allocation fails in edac_mc_alloc()CVE-2026-31689 · Linux EDAC/mc - error path ordering in edac_mc_alloc()Medium
- Linux iommu/vt-d (dev-IOTLB flush in scalable mode): The scalable-mode half of the device-IOTLB invalidation problem —CVE-2026-43130 · Linux iommu/vt-d (dev-IOTLB flush in scalable mode)Medium
- Linux iommu/vt-d (dev-IOTLB flush for passed-through PCIe devices): The Intel IOMMU driver skips device-IOTLBCVE-2026-43161 · Linux iommu/vt-d (dev-IOTLB flush for passed-through PCIe devices)Medium
- Linux amd-pstate - memory leak in amd_pstate_epp_cpu_init(): On failure to set the energy-performance preferenceCVE-2026-53121 · Linux amd-pstate - memory leak in amd_pstate_epp_cpu_init()Medium
- Linux iommu/amd - devid bounds check in __rlookup_amd_iommu(): The AMD IOMMU driver looked up device IDs withoutCVE-2026-53283 · Linux iommu/amd - devid bounds check in __rlookup_amd_iommu()Medium
- Linuxfabrik monitoring plugins: sudo-authorized checks read arbitrary root-readable files via --testCVE-2026-73974 · Linuxfabrik Monitoring Plugins / linuxfabrik-lib (lib.lftest.test --test path handling)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.