CVE-2026-7487CWE-1280

CVE-2026-7487

Low · published August 26, 2026

CVSS v3.1
3.5
EPSS
0%
Percentile
13.1
In the wild
Unconfirmed
What it is

GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.

The record
Technical detail
CVSS v3.1
3.5 · LOW
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00225 · 13.1th percentile
Weakness
CWE-1280 · Access Control Check Implemented After Asset is Accessed
Published
2026-08-26T18:17Z
Affected products (3)
ProductVersionsFixed in
gitlab/gitlab≥ 13.1.0, < 19.1.719.1.7
gitlab/gitlab≥ 19.2.0, < 19.2.519.2.5
gitlab/gitlaball versions
References (3)
EPSS history
Timeline
  • 28 AUG 06:54Z
    EPSS moved — → 0%
    epss
  • 26 AUG 13:36Z
    Access Control Check Implemented After Asset is Accessed in GitLab
    cvelistv5