GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: developer-level user can run a policy test pipeline and read protected CI/CD variables

CVSS 8.5CVE-2026-79708Control plane, storage & DevOpscurated

Impact

Insufficient scope validation let an authenticated user with Developer permissions execute a policy test pipeline against projects in their group and read protected CI/CD variables that were meant to be restricted to higher-privileged roles. Protected variables are where fleets keep registry credentials, cloud keys and deploy tokens, so this is a privilege-escalation path from ordinary repository access to the secrets that build and push the images a GPU cluster runs. Affects GitLab EE 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

Who can reach it

Authenticated GitLab EE user holding Developer permissions on a project in the group, reachable over the network wherever the GitLab instance is exposed. No admin or maintainer role required.

What to do

Upgrade to GitLab EE 19.1.8, 19.2.6 or 19.3.2 and restart the service - a standard GitLab patch upgrade, no node maintenance. Because the flaw exposes secrets, rotate any protected CI/CD variables that were readable by Developer-level users on affected instances; upgrading alone does not undo a leak.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.