CVE-2026-3035
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-3035 is an improper authorization vulnerability in GitLab Enterprise Edition (EE) that allows an authenticated user with project Maintainer permissions to access the terminal of a protected environment they are not authorized to use. The flaw affects all GitLab EE versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1. It was published on August 26, 2026, and GitLab has released patches for all affected branches. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), where GitLab EE fails to properly enforce authorization checks when a Maintainer-role user attempts to access protected environment terminals. Under certain conditions, the authorization gate for protected environment terminal access can be bypassed, allowing a Maintainer to interact with terminals scoped to higher-privilege environments. The attack is network-based, requires no user interaction, and requires the attacker to already hold Maintainer-level project permissions. The vulnerability was originally reported via HackerOne (report #3529751) (GitHub Advisory).

Impact

Successful exploitation allows an authenticated Maintainer to access and interact with protected environment terminals beyond their assigned authorization scope, resulting in low confidentiality and low integrity impact with no availability impact. An attacker could potentially read sensitive environment variables, configuration data, or secrets exposed in the terminal session, and could execute commands within the protected environment. The changed scope indicator in the CVSS score reflects that the impact extends beyond the component the attacker is authorized to access (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with at least Maintainer-level project permissions, limiting the attacker pool (GitHub Advisory).

Exploitation steps

  1. Obtain Maintainer Access: Authenticate to a GitLab EE instance as a user with project Maintainer permissions on a project that has protected environments configured.
  2. Identify Protected Environments: Enumerate the project's environments (via the GitLab UI or API) to identify protected environments for which the Maintainer account lacks explicit terminal access authorization.
  3. Trigger Authorization Bypass: Under the specific conditions that trigger the improper authorization check, navigate to or craft a request targeting the terminal endpoint of a protected environment (e.g., via the GitLab web terminal UI or API endpoint for environment terminals).
  4. Access Terminal: Due to the missing or bypassed authorization check, gain interactive terminal access to the protected environment's runner or deployment target.
  5. Interact with Environment: Execute commands within the protected environment terminal to read secrets, environment variables, or configuration data, or to perform unauthorized actions within that environment's scope (GitHub Advisory).

Indicators of compromise

  • Logs: GitLab application logs showing terminal session initiation (/environments/:id/terminal) by users with Maintainer roles on protected environments they are not explicitly authorized to access.
  • Logs: Audit log entries in GitLab EE recording terminal access events for protected environments, particularly from accounts that should not have such access.
  • Network: Unexpected WebSocket connections from Maintainer-level user sessions to protected environment terminal endpoints.
  • Behavioral: Maintainer-role users accessing environment terminal sessions in projects where they have not been granted explicit protected environment access (GitHub Advisory).

Mitigation and workarounds

GitLab has released patched versions: 19.1.7, 19.2.5, and 19.3.1. All GitLab EE installations running versions from 11.3 onward should upgrade to one of these fixed releases immediately. As a compensating control prior to patching, administrators should audit and restrict Maintainer-level user assignments on projects with sensitive protected environments, and review GitLab audit logs for any unauthorized terminal access. GitLab.com (SaaS) has already been patched (GitHub Advisory, GitLab Patch Release).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18252HIGH7.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-3035MEDIUM5.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-15387MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management