CVE-2026-15831CWE-1270

CVE-2026-15831

Medium · published July 30, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
12.6
In the wild
Unconfirmed
What it is

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00222 · 12.6th percentile
Weakness
CWE-1270 · Generation of Incorrect Security Tokens
Published
2026-07-30T00:17Z
Affected products (2)
ProductVersionsFixed in
gitlab/gitlab≥ 19.1.0, < 19.1.319.1.3
gitlab/gitlaball versions
References (2)
EPSS history
Timeline
  • 29 JUL 19:00Z
    Generation of Incorrect Security Tokens in GitLab
    cvelistv5