Junglewise Threat Intelligence

CVE-2026-15387: GitLab EE improper handling of untrusted data in Pipeline Execution Policies

CVE-2026-15387 · Severity: medium · CVSS 4.3 · Published 2026-08-26

Technologies: GitLab EE. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition's Pipeline Execution Policies feature improperly handles job dependencies, allowing a developer with code access to manipulate the execution environment of security policy enforcement jobs. An attacker could modify the execution context or bypass intended policy checks, potentially allowing malicious code to run without proper enforcement.

Technical details

This vulnerability is an improper handling of untrusted data issue in GitLab EE's Pipeline Execution Policies implementation. The root cause is insufficient validation of job dependency data when enforcement jobs are prepared. An authenticated user with developer-role permissions can manipulate job dependencies to influence the execution environment of policy enforcement jobs. The attack requires network access and valid GitLab credentials with developer permissions on a project. Patches are available in GitLab 19.1.7, 19.2.5, and 19.3.1 for EE versions 19.1+, and backports should be applied to all affected versions from 19.1 onward.

Affected products

  • GitLab GitLab EE 19.1 before 19.1.7, 19.2 before 19.2.5, 19.3 before 19.3.1

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Patches released in versions 19.1.7, 19.2.5, and 19.3.1

References

Related threats