CVE-2026-3035
GitLab Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-3035 is an improper authorization vulnerability in GitLab Enterprise Edition (EE) that allows an authenticated user with project Maintainer permissions to access the terminal of a protected environment they are not authorized to use. The flaw affects all GitLab EE versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1. It was published on August 26, 2026, and GitLab has released patches for all affected branches. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory).

Détails techniques

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), where GitLab EE fails to properly enforce authorization checks when a Maintainer-role user attempts to access protected environment terminals. Under certain conditions, the authorization gate for protected environment terminal access can be bypassed, allowing a Maintainer to interact with terminals scoped to higher-privilege environments. The attack is network-based, requires no user interaction, and requires the attacker to already hold Maintainer-level project permissions. The vulnerability was originally reported via HackerOne (report #3529751) (GitHub Advisory).

Impact

Successful exploitation allows an authenticated Maintainer to access and interact with protected environment terminals beyond their assigned authorization scope, resulting in low confidentiality and low integrity impact with no availability impact. An attacker could potentially read sensitive environment variables, configuration data, or secrets exposed in the terminal session, and could execute commands within the protected environment. The changed scope indicator in the CVSS score reflects that the impact extends beyond the component the attacker is authorized to access (GitHub Advisory).

Exploitabilité

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with at least Maintainer-level project permissions, limiting the attacker pool (GitHub Advisory).

Étapes d’exploitation

  1. Obtain Maintainer Access: Authenticate to a GitLab EE instance as a user with project Maintainer permissions on a project that has protected environments configured.
  2. Identify Protected Environments: Enumerate the project's environments (via the GitLab UI or API) to identify protected environments for which the Maintainer account lacks explicit terminal access authorization.
  3. Trigger Authorization Bypass: Under the specific conditions that trigger the improper authorization check, navigate to or craft a request targeting the terminal endpoint of a protected environment (e.g., via the GitLab web terminal UI or API endpoint for environment terminals).
  4. Access Terminal: Due to the missing or bypassed authorization check, gain interactive terminal access to the protected environment's runner or deployment target.
  5. Interact with Environment: Execute commands within the protected environment terminal to read secrets, environment variables, or configuration data, or to perform unauthorized actions within that environment's scope (GitHub Advisory).

Indicateurs de compromis

  • Logs: GitLab application logs showing terminal session initiation (/environments/:id/terminal) by users with Maintainer roles on protected environments they are not explicitly authorized to access.
  • Logs: Audit log entries in GitLab EE recording terminal access events for protected environments, particularly from accounts that should not have such access.
  • Network: Unexpected WebSocket connections from Maintainer-level user sessions to protected environment terminal endpoints.
  • Behavioral: Maintainer-role users accessing environment terminal sessions in projects where they have not been granted explicit protected environment access (GitHub Advisory).

Atténuation et solutions de contournement

GitLab has released patched versions: 19.1.7, 19.2.5, and 19.3.1. All GitLab EE installations running versions from 11.3 onward should upgrade to one of these fixed releases immediately. As a compensating control prior to patching, administrators should audit and restrict Maintainer-level user assignments on projects with sensitive protected environments, and review GitLab audit logs for any unauthorized terminal access. GitLab.com (SaaS) has already been patched (GitHub Advisory, GitLab Patch Release).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté GitLab Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-18252HIGH8.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiAug 26, 2026
CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • gitlab
NonOuiAug 26, 2026
CVE-2026-3035MEDIUM5.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiAug 26, 2026
CVE-2026-15387MEDIUM4.3
  • GitLab logoGitLab
  • gitlab-rails-19.2
NonOuiAug 26, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • gitlab-rails-19.2
NonOuiAug 26, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités