CVE-2026-13210
Incorrect Authorization in GitLab
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.
In plain language
AI Worth attentiongitlab versions from 15.7 through affected 19.1, 19.2, and 19.3 releases can let a signed-in user view deployment secrets meant for another environment; businesses running gitlab should upgrade.
Authenticated incorrect authorization in gitlab’s environment-scope pattern matcher can expose CI/CD variables outside their intended environment scope.
What to do now
- Check the version of each gitlab server you run and identify whether it is below the corrected release for its version branch.
- Upgrade 19.1 installations to 19.1.8 or later, 19.2 installations to 19.2.6 or later, and 19.3 installations to 19.3.2 or later.
- After upgrading, review and replace sensitive deployment passwords or keys stored in automated-build settings where appropriate.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-13210 and every CVE in our database. Create a free account — no credit card required.
Create Free Account