← Back

CVE-2026-15387

nvd nist
Published: Aug 26, 2026Modified: Aug 31, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: cve@gitlab.com (Secondary)

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.

Affected (3)

Products: Gitlab: Gitlab
1 product
Gitlab
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Gitlab
From 19.1.0 to 19.1.7
From 19.2.0 to 19.2.5
Version 19.3.0

References (3)

Source: cve@gitlab.com
Issue TrackingVendor Advisory
Source: cve@gitlab.com
Permissions RequiredThird Party Advisory

Timeline

No history available yet.