3.5
CVE-2026-7487
- EPSS 0.23%
- Veröffentlicht 26.08.2026 13:36:25
- Zuletzt bearbeitet 31.08.2026 15:43:30
- Erkennungen
Access Control Check Implemented After Asset is Accessed in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@gitlab.com | 3.5 | 2.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
|
CWE-1280 Access Control Check Implemented After Asset is Accessed
A product's hardware-based access control check occurs after the asset has been accessed.
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/
https://gitlab.com/gitlab-org/gitlab/-/work_items/598657
https://hackerone.com/reports/3669140