SB2026073054 - Multiple vulnerabilities in GitLab CE/EE
Published: July 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 13 vulnerabilities.
1) Incorrect authorization (CVE-ID: CVE-2026-15831)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to bypass administrator-configured tool governance policies.
The vulnerability exists due to improper authorization enforcement in Duo Workflows token generation when generating security tokens. A remote user can generate a token to bypass administrator-configured tool governance policies.
2) Input validation error (CVE-ID: CVE-2026-12436)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to modify CI/CD configuration belonging to another user.
The vulnerability exists due to improper input validation in the Pipeline Schedule API when processing pipeline schedule inputs. A remote user can supply crafted attributes to modify CI/CD configuration belonging to another user.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-15975)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to insufficient resource throttling in merge request discussions when processing merge request discussions. A remote attacker can send requests to cause a denial of service.
4) Race condition (CVE-ID: CVE-2026-13113)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to merge code into a protected branch without the required approvals.
The vulnerability exists due to a race condition in merge request approval rule processing when processing approval rules. A remote user can trigger the race condition to merge code into a protected branch without the required approvals.
5) Information disclosure (CVE-ID: CVE-2026-16553)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to disclose sensitive information to an unintended host.
The vulnerability exists due to improper handling of upstream requests in virtual registries when processing upstream requests. A remote user can trigger upstream requests to disclose sensitive information to an unintended host.
6) Missing Authorization (CVE-ID: CVE-2026-6336)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to view project import source information.
The vulnerability exists due to improper access control in project import status when handling requests. A remote attacker can access the project import status to view project import source information.
7) Incorrect authorization (CVE-ID: CVE-2026-14341)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to modify protected branch configuration.
The vulnerability exists due to improper authorization in a projects API endpoint when handling API requests. A remote privileged user can send a crafted API request to modify protected branch configuration.
The issue affects users with the Maintainer role under certain conditions.
8) Cross-site scripting (CVE-ID: CVE-2026-3093)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in paginated views when a victim visits a crafted URL. A remote attacker can send a crafted URL to execute arbitrary JavaScript in another user's browser.
User interaction is required for the victim to open the crafted URL.
CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to access information from unauthorized projects.
The vulnerability exists due to improper neutralization of untrusted content in Duo Code Review when processing AI-assisted code review content. A remote user can submit crafted untrusted content to access information from unauthorized projects.
10) Improper access control (CVE-ID: CVE-2026-6267)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to access unauthorized information.
The vulnerability exists due to improper access control in Workhorse internal request handling when processing internal requests. A remote user can send a crafted request to access unauthorized information.
The issue affects authenticated users with the Developer role under certain conditions.
11) Incorrect authorization (CVE-ID: CVE-2026-14351)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to view the title of a confidential issue.
The vulnerability exists due to improper authorization checks in merge request title generation when generating titles for publicly accessible merge requests. A remote user can access a publicly accessible merge request to view the title of a confidential issue.
12) Improper access control (CVE-ID: CVE-2026-4672)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to access test report contents they are not authorized to view.
The vulnerability exists due to improper access control enforcement in the Pipeline Test Report API when handling API requests. A remote user can send a request to access test report contents they are not authorized to view.
The issue affects users with guest-role permissions under certain conditions.
13) Incorrect authorization (CVE-ID: CVE-2025-14562)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to commit changes to a project after being removed as a member.
The vulnerability exists due to improper authorization checks in merge request collaboration settings when handling collaboration settings. A remote user can use merge request collaboration settings to commit changes to a project after being removed as a member.
The issue affects users who previously had developer-role permissions.
Remediation
Install update from vendor's website.