SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-7487

LOW · CVSS 3.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

GitLab versions from 13.1 to 19.1.7, 19.2 to 19.2.5, and 19.3 to 19.3.1 are vulnerable to an issue where authenticated users with reporter-role permissions can reset merge request approval rules due to inadequate authorization checks. This could potentially allow unauthorized changes to merge request approvals, impacting the integrity of the code review process. Organizations using affected GitLab versions, especially those with collaborative development environments, should prioritize applying the necessary updates to mitigate this risk.

CVE
CVE-2026-7487
Severity
LOW
CVSS
3.5
EPSS
0.22%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)