CVE-2026-15387CWE-349

CVE-2026-15387

Medium · published August 26, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
10.5
In the wild
Unconfirmed
What it is

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00204 · 10.5th percentile
Weakness
CWE-349 · Acceptance of Extraneous Untrusted Data With Trusted Data
Published
2026-08-26T18:17Z
Affected products (3)
ProductVersionsFixed in
gitlab/gitlab≥ 19.1.0, < 19.1.719.1.7
gitlab/gitlab≥ 19.2.0, < 19.2.519.2.5
gitlab/gitlaball versions
References (3)
EPSS history
Timeline
  • 28 AUG 06:31Z
    EPSS moved — → 0%
    epss
  • 26 AUG 13:36Z
    Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
    cvelistv5