LOW
Access Control Check Implemented After Asset is Accessed in GitLab
Published Aug 26, 2026
3.5
LOWCVSS 3.1
EPSS 0.32%
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.
Affected products
-
- Version 13.1StatusaffectedConstraints<19.1.7
- Version 19.2StatusaffectedConstraints<19.2.5
- Version 19.3StatusaffectedConstraints<19.3.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 19.1.7, 19.2.5, 19.3.1 or above.
Weaknesses (1)
References (3)
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ Release NotesVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/598657 Issue TrackingPermissions Required
- https://hackerone.com/reports/3669140 technical-descriptionexploitpermissions-requiredPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/ | Release NotesVendor Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/work_items/598657 | Issue TrackingPermissions Required | |
| https://hackerone.com/reports/3669140 | technical-descriptionexploitpermissions-requiredPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Aug 26, 2026
Updated Aug 26, 2026
Reserved Apr 30, 2026
Link CVE-2026-7487
CISA Vulnrichment
Updated Aug 26, 2026