GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: project Maintainer can open a terminal on a protected environment they are not authorized for

CVE-2026-3035Control plane, storage & DevOpscurated

Impact

Protected environments exist so that only a named set of users can touch production deployments; this bug lets any project Maintainer bypass that gate and open the environment's web terminal. On a fleet where GitLab drives model deployment, that terminal is an interactive shell inside the running deployment's container, with whatever service credentials and mounted volumes it holds. The scope is marked changed in the vendor's own scoring, meaning access reaches beyond the GitLab instance into the deployed workload. Anyone who has been given Maintainer on a project for ordinary reasons - CI configuration, runner registration - inherits access to environments the org deliberately restricted.

Who can reach it

An authenticated GitLab user holding project Maintainer permissions on an affected project. No administrator rights and no access to the environment itself are required.

What to do

Upgrade GitLab EE to 19.3.1, 19.2.5 or 19.1.7 depending on branch; GitLab.com is already patched. This is a package upgrade plus a restart of the GitLab services (Puma/Sidekiq) - no node drain or reboot. Until then, audit who holds Maintainer on projects that own protected environments and review terminal session logs for that period.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.