Junglewise Threat Intelligence

CVE-2026-79708: GitLab EE scheduled pipeline execution policy test privilege escalation

CVE-2026-79708 · Severity: high · CVSS 8.5 · Published 2026-09-16

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition contains an authorization flaw in its scheduled pipeline execution feature that allows developers to bypass access restrictions on protected CI/CD variables. An authenticated developer can execute a policy test pipeline to access variables that should only be available to higher-privileged roles, potentially exposing sensitive secrets used in the CI/CD pipeline.

Technical details

The vulnerability is an insufficient scope validation flaw in GitLab EE's scheduled pipeline execution policy feature. An authenticated user with developer permissions can trigger a policy test pipeline that bypasses authorization checks, allowing them to access protected CI/CD variables restricted to maintainers or other higher-privileged roles. The attack requires authentication and network access to the GitLab instance, but no user interaction beyond executing a pipeline. The vulnerability was patched in versions 19.1.8, 19.2.6, and 19.3.2.

Affected products

  • GitLab Enterprise Edition 19.0 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2

Timeline

  • 2026-09-16: disclosed
  • 2026-09-10: patched

References

Related threats