VYPR
Published Aug 26, 2026· Updated Aug 27, 2026· 1 source

GitLab EE: Five Vulnerabilities Including High-Severity Command Execution Patched Together

Key findings • GitLab EE patched five vulnerabilities on August 26, 2026, including one High severity command execution flaw. • Vulnerabilities addressed include improper authorization, unaut…

Key findings

  • GitLab EE patched five vulnerabilities on August 26, 2026, including one High severity command execution flaw.
  • Vulnerabilities addressed include improper authorization, unauthorized terminal access, DoS via SCIM, and CI/CD environment manipulation.
  • All affected versions are prior to 19.1.7, 19.2.5, and 19.3.1.
  • Patched versions are 19.1.7, 19.2.5, and 19.3.1; immediate upgrades are recommended for self-managed instances.

On August 26, 2026, GitLab Inc. released security updates addressing five vulnerabilities in GitLab Enterprise Edition (EE). The disclosures, all occurring on the same day, include issues ranging from low to high severity, impacting various functionalities within the platform. These vulnerabilities affect all versions prior to 19.1.7, 19.2.5, and 19.3.1, with GitLab strongly recommending immediate upgrades for all self-managed installations.

One of the more severe issues, CVE-2026-18252, is rated as High severity. This vulnerability, affecting versions prior to 19.1.7, 19.2.5, and 19.3.1, could allow an authenticated user with developer-role permissions to execute arbitrary commands in a CI context due to improper handling of configurations by the Claude agent.

Several medium-severity vulnerabilities were also patched. CVE-2026-3035 allows an authenticated user with project Maintainer permissions to access the terminal of a protected environment they should not have access to. Additionally, CVE-2025-10903, a denial of service vulnerability, could be triggered by specially crafted input in the SCIM user provisioning feature, affecting versions prior to 19.1.7, 19.2.5, and 19.3.1. Another medium-severity flaw, CVE-2026-15387, could allow an authenticated user with developer-role permissions to influence the execution environment of Pipeline Execution Policy enforcement jobs.

A low-severity vulnerability, CVE-2026-7487, was also addressed. This issue could allow an authenticated user with reporter-role permissions to reset merge request approval rules due to improper authorization checks. This affected all versions prior to 19.1.7, 19.2.5, and 19.3.1.

The fixes for all five vulnerabilities were rolled out in patch releases 19.1.7, 19.2.5, and 19.3.1. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. Users with self-managed installations are urged to upgrade immediately to one of the patched versions to mitigate these security risks. The coordinated disclosure of these vulnerabilities highlights the importance of timely patching for maintaining the security posture of GitLab environments. N1

The patched versions are 19.1.7, 19.2.5, and 19.3.1. All affected versions are prior to these releases. N2

Synthesized by Vypr AI