Incorrect authorization in GitLab Enterprise Edition - CVE-2026-92529
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control.
The vulnerability exists due to improper authorization checks in Duo Workflow Service token governance enforcement when processing workflows. A remote user can process a workflow to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control.
Exploitation requires developer-role permissions.