Executive brief
GitLab Enterprise Edition contains an authorization flaw in its scheduled pipeline execution feature that allows developers to bypass access restrictions on protected CI/CD variables. An authenticated developer can execute a policy test pipeline to access variables that should only be available to higher-privileged roles, potentially exposing sensitive secrets used in the CI/CD pipeline.
Technical details
The vulnerability is an insufficient scope validation flaw in GitLab EE's scheduled pipeline execution policy feature. An authenticated user with developer permissions can trigger a policy test pipeline that bypasses authorization checks, allowing them to access protected CI/CD variables restricted to maintainers or other higher-privileged roles. The attack requires authentication and network access to the GitLab instance, but no user interaction beyond executing a pipeline. The vulnerability was patched in versions 19.1.8, 19.2.6, and 19.3.2.
Affected products
- GitLab Enterprise Edition 19.0 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2
Timeline
- 2026-09-16: disclosed
- 2026-09-10: patched