Executive brief
GitLab Enterprise Edition contains an authorization flaw in its compliance framework feature that allows authenticated users with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables in group projects without proper permission checks. This could allow a Security Manager to access sensitive pipeline secrets and run unauthorized automation tasks, potentially compromising the integrity and confidentiality of CI/CD operations.
Technical details
The vulnerability is an improper authorization control issue in GitLab EE's compliance framework management that affects versions 18.11 through 19.3.1. An authenticated user with the Security Manager role can exploit insufficient permission validation to execute arbitrary CI/CD jobs and read protected variables within group projects. The flaw requires authentication and the specific Security Manager role assignment, but once those conditions are met, an attacker can access sensitive pipeline variables and execute unauthorized jobs. Patches are available in versions 19.1.8, 19.2.6, and 19.3.2.
Affected products
- GitLab GitLab Enterprise Edition 18.11 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2
Timeline
- 2026-09-16: disclosed: CVE-2026-16794 disclosed
- 2026-09-10: patched: Patches released in versions 19.1.8, 19.2.6, and 19.3.2