Missing Authorization in GitLab Enterprise Edition - CVE-2026-16794
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary CI/CD jobs and access protected variables within group projects.
The vulnerability exists due to improper authorization controls in compliance framework management when managing compliance frameworks. A remote user can manage compliance frameworks to execute arbitrary CI/CD jobs and access protected variables within group projects.
Exploitation requires the Security Manager role.