Database/Control plane, storage & DevOps
GitLab EE: missing namespace validation lets a user apply compliance frameworks from namespaces they cannot access
Impact
On self-managed GitLab EE, an authenticated user could attach a compliance framework belonging to a namespace they have no rights to onto a project they control, because the assignment path did not validate namespace membership. The consequence established by the record is integrity of compliance metadata: the framework applied to a project, and therefore the policy set and audit posture reported for it, can be made to disagree with what the owning namespace intended. For a GPU shop that uses GitLab as the CI/CD path building and signing the container images the fleet runs, compliance frameworks are often the hook that decides which pipeline policies and approval rules apply, so a wrong framework can quietly weaken or confuse that gating. No repository access, code execution or credential disclosure is claimed - this is a scoped authorization defect, not a takeover.
Who can reach it
Any authenticated user on a self-managed GitLab EE instance who owns or maintains a project and can reach the web UI or API. No administrator rights and no membership in the victim namespace are needed.
What to do
Upgrade to GitLab 19.1.7, 19.2.5 or 19.3.1 depending on your stream (all versions from 18.3 are affected). This is an application upgrade and reconfigure on the GitLab host or a rolling restart of the GitLab pods - GPU nodes are untouched and no maintenance window on the fleet is needed. GitLab.com is not affected; the issue is specific to self-managed instances.
References
Related entries
- LibreNMS: reflected XSS in the Proxmox view runs script in a logged-in monitoring user's sessionCVE-2026-45694 · LibreNMS (Proxmox application view, instance and vmid parameters)Medium
- CloudNativePG instance manager (status server, TCP/8000 control endpoints): A set of operator-only control endpointsNCVD-2026-050-cloudnativepg-instance-manager-s · CloudNativePG instance manager (status server, TCP/8000 control endpoints)Medium
- Slurm (user_name / gid field handling): Slurm trusts the user_name and gid fields carried in job RPCs instead ofCVE-2018-10995 · Slurm (user_name / gid field handling)Medium
- IBM Spectrum LSF (job submission, file permissions): Weak file permissions in the LSF install let a local user changeCVE-2018-1724 · IBM Spectrum LSF (job submission, file permissions)Medium
- AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): Insufficient RMP checking on IOMMU host bufferCVE-2023-20585 · AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016)Medium
- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorCVE-2023-38958 · ZKTeco BioAccess IVS v3.3.1 access control platformMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.