CVE-2026-12436Patch(gitlab / gitlab)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to improper validation of user-supplied attributes when processing pipeline schedule inputs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
gitlab

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-07: 108-07
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • iototsecnews@iototsecnews
    Patch

    GitLab の 13 件の脆弱性が FIX:不正なデータ露出/CI/CD パイプラインの改ざん/DoS 攻撃などの恐れ https://iototsecnews.jp/2026/07/30/gitlab-patches-13-security-flaws-enabling-data-exposure-ci-cd-tampering-and-dos-attacks/ GitLab において、内部のアクセス制御や検証処理の不備に起因する、複数の脆弱性 CVE-2026-6267/CVE-2026-12436/CVE-2026-15975 などが公表されました。この問題は、ユーザーからの入力検証やリソース管理が不十分なことに起因しています。悪用に成功した攻撃者が、非公開情報の閲覧や CI/CD 設定の不正書き換えを行い、さらには承認ルールを回避したコードの追加やシステムの応答停止を引き起こす恐れがあります。対応策として、修正パッチを含む最新バージョンへの更新と異常なログの確認が有効です。システムを安全に利用するためにも、速やかにアップデートを実施することが推奨されます。 #GitLab #Vulnerability

    Post summary

    GitLab disclosed 13 security flaws that could lead to data exposure, CI/CD tampering, and DoS, and urged users to apply the latest patched releases and monitor logs for abnormal activities.

    01000176
    505 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---
Appgitlabgitlab19.2.0--
Appgitlabgitlab19.2.0--

Explore more