Input validation error in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-12436
Published: July 29, 2026 / Updated: July 30, 2026
GitLab Enterprise Edition
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote user to modify CI/CD configuration belonging to another user.
The vulnerability exists due to improper input validation in the Pipeline Schedule API when processing pipeline schedule inputs. A remote user can supply crafted attributes to modify CI/CD configuration belonging to another user.