
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3035 is an improper authorization vulnerability in GitLab Enterprise Edition (EE) that allows an authenticated user with project Maintainer permissions to access the terminal of a protected environment they are not authorized to use. The flaw affects all GitLab EE versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1. It was published on August 26, 2026, and GitLab has released patches for all affected branches. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), where GitLab EE fails to properly enforce authorization checks when a Maintainer-role user attempts to access protected environment terminals. Under certain conditions, the authorization gate for protected environment terminal access can be bypassed, allowing a Maintainer to interact with terminals scoped to higher-privilege environments. The attack is network-based, requires no user interaction, and requires the attacker to already hold Maintainer-level project permissions. The vulnerability was originally reported via HackerOne (report #3529751) (GitHub Advisory).
Successful exploitation allows an authenticated Maintainer to access and interact with protected environment terminals beyond their assigned authorization scope, resulting in low confidentiality and low integrity impact with no availability impact. An attacker could potentially read sensitive environment variables, configuration data, or secrets exposed in the terminal session, and could execute commands within the protected environment. The changed scope indicator in the CVSS score reflects that the impact extends beyond the component the attacker is authorized to access (GitHub Advisory).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with at least Maintainer-level project permissions, limiting the attacker pool (GitHub Advisory).
/environments/:id/terminal) by users with Maintainer roles on protected environments they are not explicitly authorized to access.GitLab has released patched versions: 19.1.7, 19.2.5, and 19.3.1. All GitLab EE installations running versions from 11.3 onward should upgrade to one of these fixed releases immediately. As a compensating control prior to patching, administrators should audit and restrict Maintainer-level user assignments on projects with sensitive protected environments, and review GitLab audit logs for any unauthorized terminal access. GitLab.com (SaaS) has already been patched (GitHub Advisory, GitLab Patch Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."