Junglewise Threat Intelligence

CVE-2026-15831: GitLab Enterprise Edition policy bypass in Duo Workflows

CVE-2026-15831 · Severity: medium · CVSS 4.3 · Published 2026-07-29

Executive brief

GitLab Enterprise Edition, a platform for software development and collaboration, contained a flaw in its Duo Workflows component. This vulnerability could allow a registered user to bypass security policies set by administrators to govern the use of automated tools. While it does not directly expose data, it allows users to circumvent organizational compliance and governance controls.

Technical details

An improper authorization vulnerability (CWE-1270) exists in GitLab EE's Duo Workflows component. The flaw occurs during the generation of security tokens, where the system fails to properly enforce administrator-configured tool governance policies. An authenticated attacker with network access can exploit this to generate tokens that bypass these governance restrictions. The issue affects GitLab EE versions 19.1 before 19.1.3 and 19.2 before 19.2.1. Patches have been released in versions 19.1.3 and 19.2.1.

Affected products

  • GitLab GitLab Enterprise Edition 19.1 before 19.1.3, 19.2 before 19.2.1

Timeline

  • 2026-07-29: patched: GitLab released versions 19.2.1 and 19.1.3 to address the issue.
  • 2026-07-29: advisory: NVD and GitLab published the vulnerability details.

References

Related threats