Database/Control plane, storage & DevOps
GitLab EE: reporter-role author of a merge request can reset its approval rules
Impact
Approval rules are the gate that stops one person from pushing a change into a protected branch unreviewed. A missing authorization check lets a reporter-role user who authored a merge request reset the approval rules on that request, so the review requirement can be cleared by exactly the person it exists to constrain. Where GitLab is the source of truth for infrastructure manifests, runner images, or model deployment config, that is a supply chain integrity issue rather than a data exposure one. Rated low integrity impact only, and the vector records that user interaction is required. Affects all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1.
Who can reach it
An authenticated GitLab user with reporter-role permissions who is the author of the merge request. The CVSS vector also records required user interaction.
What to do
Upgrade to GitLab EE 19.1.7, 19.2.5, or 19.3.1, the same patch release that carries CVE-2026-15387. Self-managed instances take a package upgrade and an application restart; no node or runner maintenance is involved.
References
Related entries
- IBM Spectrum Scale Local Read Only Cache (LROC): With LROC enabled, a read of one file can silently return the contentsCVE-2018-1993 · IBM Spectrum Scale Local Read Only Cache (LROC)Low
- DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issue: TurnsCVE-2019-0174 · DDR3 and DDR4 DRAM, including ECC modules; tracked by Intel as a partial-physical-address disclosure issueLow
- IBM Spectrum Scale file audit logging: A local user touches files without the access being recorded, so the audit trailCVE-2021-29671 · IBM Spectrum Scale file audit loggingLow
- Redis: Crafted Lua script triggers a NULL pointer dereferenceCVE-2022-24736 · RedisLow
- GitLab EE: pending members receive custom-role permissions before their membership is activeCVE-2025-9486 · GitLab EE (custom role assignment, pending membership state)Low
- Grafana: legacy correlation records can be read and permanently deleted across organizationsCVE-2026-21727 · Grafana (Correlations feature, legacy org_id = 0 records)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.