SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-15387

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

GitLab versions prior to 19.1.7, 19.2.5, and 19.3.1 are vulnerable to an issue where authenticated users with developer-role permissions can manipulate the execution environment of Pipeline Execution Policy enforcement jobs due to improper handling of job dependencies. This vulnerability could lead to unauthorized actions within the CI/CD pipeline, potentially compromising project integrity. Organizations using affected GitLab versions should prioritize remediation to mitigate risks associated with this vulnerability.

CVE
CVE-2026-15387
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.

Related CVEs

Other vulnerabilities affecting the same vendor(s)