Executive brief
GitLab Enterprise Edition contains a security flaw that could allow certain authorized users to bypass workflow restrictions. Specifically, users with 'Developer' permissions could circumvent rules intended to control foundational flows at the group level. This could lead to unauthorized changes or actions that violate an organization's internal compliance or development policies.
Technical details
A missing authorization vulnerability (CWE-862) exists in GitLab EE affecting versions 18.7 through 19.0.0. When foundational flows are enabled at the group level, the application fails to properly enforce flow restrictions against users holding the Developer role. An authenticated attacker with network access and Developer-level permissions can exploit this to bypass intended workflow constraints. The issue is remediated in versions 18.10.7, 18.11.4, and 19.0.1.
Affected products
- GitLab GitLab Enterprise Edition (EE) 18.7 to < 18.10.7, 18.11 to < 18.11.4, 19.0 to < 19.0.1
Timeline
- 2026-05-27: disclosed
- 2026-05-27: patched
- 2026-05-27: advisory