Database/Control plane, storage & DevOps
GitLab EE: developer-level user can run a policy test pipeline and read protected CI/CD variables
Impact
Insufficient scope validation let an authenticated user with Developer permissions execute a policy test pipeline against projects in their group and read protected CI/CD variables that were meant to be restricted to higher-privileged roles. Protected variables are where fleets keep registry credentials, cloud keys and deploy tokens, so this is a privilege-escalation path from ordinary repository access to the secrets that build and push the images a GPU cluster runs. Affects GitLab EE 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.
Who can reach it
Authenticated GitLab EE user holding Developer permissions on a project in the group, reachable over the network wherever the GitLab instance is exposed. No admin or maintainer role required.
What to do
Upgrade to GitLab EE 19.1.8, 19.2.6 or 19.3.2 and restart the service - a standard GitLab patch upgrade, no node maintenance. Because the flaw exposes secrets, rotate any protected CI/CD variables that were readable by Developer-level users on affected instances; upgrading alone does not undo a leak.
References
Related entries
- GitLab EE: crafted project export import overflows the Advanced Search Unicode buffer for RCECVE-2026-88765 · GitLab EE (Advanced Search indexing, Unicode conversion buffer on project import)High
- Renovate: unescaped Gradle distributionUrl gives a repository command execution as the Renovate userCVE-2026-88886 · Renovate self-hosted (Gradle Wrapper manager, distributionUrl)High
- Renovate: unescaped Maven Wrapper distributionType lets a repository run commands in the botCVE-2026-88889 · Renovate self-hosted (Maven Wrapper manager, distributionType)High
- Ceph RGW (STS session tokens): Any tenant holding one ordinary STS session token can edit it into RGW superuser. RGWNCVD-2026-040-ceph-rgw-sts-session-tokens · Ceph RGW (STS session tokens)High
- CloudNativePG (role password handling, pg_stat_statements exposure): CREDENTIAL DISCLOSURE ACROSS THE TENANT BOUNDARYNCVD-2026-049-cloudnativepg-role-password-hand · CloudNativePG (role password handling, pg_stat_statements exposure)High
- IBM Spectrum Scale Container Native Storage Access: A local user obtains root privileges through the Spectrum ScaleCVE-2022-41736 · IBM Spectrum Scale Container Native Storage AccessHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.