GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: reporter-role author of a merge request can reset its approval rules

CVE-2026-7487Control plane, storage & DevOpscurated

Impact

Approval rules are the gate that stops one person from pushing a change into a protected branch unreviewed. A missing authorization check lets a reporter-role user who authored a merge request reset the approval rules on that request, so the review requirement can be cleared by exactly the person it exists to constrain. Where GitLab is the source of truth for infrastructure manifests, runner images, or model deployment config, that is a supply chain integrity issue rather than a data exposure one. Rated low integrity impact only, and the vector records that user interaction is required. Affects all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1.

Who can reach it

An authenticated GitLab user with reporter-role permissions who is the author of the merge request. The CVSS vector also records required user interaction.

What to do

Upgrade to GitLab EE 19.1.7, 19.2.5, or 19.3.1, the same patch release that carries CVE-2026-15387. Self-managed instances take a package upgrade and an application restart; no node or runner maintenance is involved.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.