GitLabCVE-2026-15831
GitLab: improper authorization
Medium4.3CVE-2026-15831 · Published Jul 29, 2026 · updated Aug 3, 2026
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 19.1, < 19.1.3 | 19.1.3 |
| >= 19.2, < 19.2.1 | 19.2.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1270
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | GitLab: information disclosure | High8.5 | 19.0.5+2 more |
| Jul 29 | GitLab: missing authorization | Medium5.3 | 19.0.5+2 more |
| Jul 29 | GitLab: cross-site scripting | Medium4.7 | 19.0.5+2 more |
| Jul 29 | GitLab: improper access control | Medium4.3 | 19.0.5+2 more |
| Jul 29 | GitLab: denial of service | High7.5 | 19.0.5+2 more |
| Jul 29 | GitLab: information disclosure | Medium5.4 | 19.0.5+2 more |