SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13113

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

GitLab versions from 17.0 to before 19.0.5, 19.1 to before 19.1.3, and 19.2 to before 19.2.1 are vulnerable to a race condition that may permit authenticated users to merge code into protected branches without the necessary approvals. This flaw could lead to unauthorized code changes, potentially compromising the integrity of the codebase. Organizations using affected versions should prioritize remediation to maintain strict control over their code review processes.

CVE
CVE-2026-13113
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due to a race condition in approval rule processing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)