Incorrect authorization in GitLab Enterprise Edition - CVE-2026-92529

 

Incorrect authorization in GitLab Enterprise Edition - CVE-2026-92529

Published: September 23, 2026


Vulnerability identifier: #VU151880
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92529
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control.

The vulnerability exists due to improper authorization checks in Duo Workflow Service token governance enforcement when processing workflows. A remote user can process a workflow to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control.

Exploitation requires developer-role permissions.


Affected software

GitLab Enterprise Edition

How to mitigate CVE-2026-92529

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1

External References

Related Security Bulletins