CVE-2026-15387
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-15387 is a pipeline execution policy tampering vulnerability in GitLab Enterprise Edition (EE) caused by improper handling of job dependencies. Under certain conditions, an authenticated user with developer-role permissions can influence the execution environment of Pipeline Execution Policy enforcement jobs. The vulnerability affects GitLab EE versions 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1. It was disclosed on August 26, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-349 (Acceptance of Extraneous Untrusted Data With Trusted Data), where GitLab EE improperly handles job dependencies during Pipeline Execution Policy enforcement. When processing trusted pipeline policy jobs, the system fails to adequately isolate untrusted data introduced via job dependency relationships, allowing a developer-role user to inject influence into the policy enforcement execution environment. The attack is network-based, requires low privileges (developer role), no user interaction, and low attack complexity. The vulnerability was originally reported via HackerOne report #3754358 (GitHub Advisory, GitLab Patch Release).

Impact

Successful exploitation allows an authenticated developer-role user to manipulate the execution environment of Pipeline Execution Policy enforcement jobs, potentially altering pipeline execution behavior and bypassing security policy controls. The integrity impact is low and scoped to the affected GitLab EE instance, with no confidentiality or availability impact assessed. This could allow a malicious insider or compromised developer account to circumvent pipeline security policies, potentially enabling unauthorized code execution paths or policy bypasses within the CI/CD pipeline (GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with at least developer-role permissions and specific pipeline configuration conditions (GitHub Advisory).

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: upgrade GitLab EE to 19.1.7, 19.2.5, or 19.3.1 or later. Organizations unable to upgrade immediately should review and restrict developer-role permissions, particularly for users who should not have the ability to modify or influence pipeline execution policies. Limiting the scope of developer access to sensitive pipeline policy configurations reduces the attack surface (GitLab Patch Release, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18252HIGH7.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-3035MEDIUM5.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-15387MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management