VYPR
Vypr IntelligenceAI-generatedAug 26, 2026· 3 CVEs

GitLab EE: Three Vulnerabilities Including Auth Bypass and DoS Patched Together

GitLab Inc. patched three vulnerabilities in GitLab EE, including authorization bypass and denial of service flaws, disclosed on August 26, 2026.

Key findings

  • GitLab EE patched three vulnerabilities on August 26, 2026, in versions 19.1.7, 19.2.5, and 19.3.1.
  • Vulnerabilities include improper authorization, unauthorized terminal access, and denial of service via SCIM.
  • All affected versions are prior to 19.1.7, 19.2.5, and 19.3.1.
  • GitLab strongly recommends immediate upgrades for self-managed installations.

On August 26, 2026, GitLab Inc. released security updates addressing three vulnerabilities in GitLab Enterprise Edition (EE), affecting versions prior to 19.1.7, 19.2.5, and 19.3.1. These vulnerabilities, disclosed together on the same day, include an authorization bypass, a denial of service flaw, and an issue allowing unauthorized access to environment terminals. The fixes were rolled out in patch releases 19.3.1, 19.2.5, and 19.1.7.

One of the disclosed vulnerabilities, CVE-2026-7487, is rated as Low severity. This flaw allowed an authenticated user with reporter-role permissions, who authored a merge request, to reset merge request approval rules under certain conditions due to improper authorization.

CVE-2026-3035, a Medium severity vulnerability, permitted an authenticated user with project Maintainer permissions to access the terminal of a protected environment they were not authorized to use. This was also a result of insufficient authorization checks.

The third vulnerability, CVE-2025-10903, also rated Medium, could lead to a denial of service. An authenticated user could trigger an unbounded loop by sending specially crafted input to the SCIM user provisioning feature.

All three vulnerabilities have been remediated in GitLab EE versions 19.1.7, 19.2.5, and 19.3.1. GitLab strongly recommends that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not require any action.

This batch of vulnerabilities highlights the importance of timely patching for self-managed GitLab instances. Users should ensure they are running the latest patched versions to protect against potential exploitation of these security weaknesses.

The CVEs disclosed in this batch are:

  • CVE-2026-7487: Improper authorization allowing reset of merge request approval rules.
  • CVE-2026-3035: Unauthorized access to protected environment terminals.
  • CVE-2025-10903: Denial of service due to unbounded loop in SCIM user provisioning.

Users are urged to update to GitLab EE 19.1.7, 19.2.5, or 19.3.1 to address these security issues. The fixes were released on August 26, 2026.

AI-written article. Grounded in 3 CVE records listed below.