
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15387 is a pipeline execution policy tampering vulnerability in GitLab Enterprise Edition (EE) caused by improper handling of job dependencies. Under certain conditions, an authenticated user with developer-role permissions can influence the execution environment of Pipeline Execution Policy enforcement jobs. The vulnerability affects GitLab EE versions 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1. It was disclosed on August 26, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).
The root cause is classified as CWE-349 (Acceptance of Extraneous Untrusted Data With Trusted Data), where GitLab EE improperly handles job dependencies during Pipeline Execution Policy enforcement. When processing trusted pipeline policy jobs, the system fails to adequately isolate untrusted data introduced via job dependency relationships, allowing a developer-role user to inject influence into the policy enforcement execution environment. The attack is network-based, requires low privileges (developer role), no user interaction, and low attack complexity. The vulnerability was originally reported via HackerOne report #3754358 (GitHub Advisory, GitLab Patch Release).
Successful exploitation allows an authenticated developer-role user to manipulate the execution environment of Pipeline Execution Policy enforcement jobs, potentially altering pipeline execution behavior and bypassing security policy controls. The integrity impact is low and scoped to the affected GitLab EE instance, with no confidentiality or availability impact assessed. This could allow a malicious insider or compromised developer account to circumvent pipeline security policies, potentially enabling unauthorized code execution paths or policy bypasses within the CI/CD pipeline (GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with at least developer-role permissions and specific pipeline configuration conditions (GitHub Advisory).
GitLab has released patched versions addressing this vulnerability: upgrade GitLab EE to 19.1.7, 19.2.5, or 19.3.1 or later. Organizations unable to upgrade immediately should review and restrict developer-role permissions, particularly for users who should not have the ability to modify or influence pipeline execution policies. Limiting the scope of developer access to sensitive pipeline policy configurations reduces the attack surface (GitLab Patch Release, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."