GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: developer-role user can modify package registry metadata without maintainer rights

CVE-2026-8667Control plane, storage & DevOpscurated

Impact

Improper authorization lets an authenticated developer-role user change certain package registry metadata that should require maintainer-level permissions. The GitLab package registry is often the source of the wheels, charts and artifacts that land on GPU nodes, so a lower-privileged account editing registry state touches the supply chain that feeds the fleet. GitLab's record limits this to metadata modification and rates integrity low - it does not describe replacing package content or publishing a new artifact, and no confidentiality or availability impact is claimed. Affects 17.6 before 19.0.6, 19.1 before 19.1.4 and 19.2 before 19.2.2.

Who can reach it

An authenticated GitLab user holding developer-role permissions on the project. Maintainer or owner role is not required; network access to the instance is.

What to do

Upgrade to 19.0.6, 19.1.4 or 19.2.2 per the GitLab 19.2.2 patch release - a package upgrade and service restart (Omnibus reconfigure/restart or a Helm chart bump), no node drain. Afterwards, review package registry metadata changes made by developer-role accounts over the affected window.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.