GitLab Patches 13 Security Flaws (incl. CVE-2026-6267, CVE-2026-12436) Enabling Data Exposure, CI/CD Tampering, and DoS — Threadlinqs Intelligence
As of 2026-08-01, GitLab Patches 13 Security Flaws (incl. CVE-2026-6267, CVE-2026-12436) Enabling Data Exposure, CI/CD Tampering, and DoS is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1806 · Severity: HIGH · CVSS: 8.5 · Status: PATCHED · Category: VULNERABILITY
GitLab shipped CE/EE 19.2.1, 19.1.3, and 19.0.5 on 2026-07-29, fixing 13 vulnerabilities: a High-severity Workhorse access-control flaw (CVE-2026-6267, CVSS 8.5), a High-severity Pipeline Schedule API
On 2026-07-29 GitLab released Community Edition (CE) and Enterprise Edition (EE) versions 19.2.1, 19.1.3, and 19.0.5, resolving 13 vulnerabilities disclosed together in a single scheduled patch release. GitLab.com (SaaS) and GitLab Dedicated were already running the patched code at release time; the advisory is aimed at self-managed CE/EE administrators, who are strongly urged to upgrade immediately.
The three highest-impact issues are CVE-2026-6267 (CVSS 8.5, CWE-201), an improper access-control flaw in GitLab Workhorse's internal request handling that lets an authenticated Developer-role user retrieve sensitive information beyond their authorization (affects all releases from 10.1.0 up to the patched versions); CVE-2026-12436 (CVSS 8.4, CWE-915), a mass-assignment flaw in the Pipeline Schedule API caused by improper validation of user-supplied attributes, allowing an authenticated low-privilege user to modify CI/CD pipeline-schedule configuration belonging to another user — a direct CI/CD-tampering and software-supply-chain risk (affects 18.0 up to the patched versions); and CVE-2026-15975 (CVSS 7.5, CWE-770), an unauthenticated denial-of-service in merge request discussions caused by insufficient resource throttling, letting an unauthenticated attacker crash or significantly degrade a self-managed instance (affects 11.8 up to the patched versions).
Ten further Medium- and Low-severity issues were fixed in the same release: CVE-2026-13113 (CVSS 6.5, CWE-367, EE-only, affects 17.0+) is a time-of-check/time-of-use race condition in merge-request approval-rule processing that could let a user merge to a protected branch without the required approvals; CVE-2026-16553 (CVSS 5.4, CWE-522, EE-only, affects 18.8+) is an insufficiently-protected-credentials flaw in Virtual Registries (GitLab's upstream package-registry proxy) that could leak credentials meant for a legitimate upstream to an unintended host; CVE-2026-6336 (CVSS 5.3, affects 16.6+) is a missing-authorization flaw exposing project-import source/status information, reported by researcher 3nvz via HackerOne; CVE-2026-14341 (CVSS 4.9, affects 12.8+) is an improper-authorization flaw in a projects API endpoint letting a Maintainer-role user modify protected-branch configuration outside their authorization; CVE-2026-3093 (CVSS 4.7, CWE-79, affects 14.0+) is a stored/reflected cross-site-scripting flaw in paginated list views; CVE-2026-15077 (CVSS 4.3, EE-only, affects 19.1+) is an indirect prompt-injection flaw in GitLab Duo Code Review — the AI code-review assistant trusts untrusted content embedded in code, commit messages, and review artifacts, letting an attacker craft content that redirects the AI backend to disclose data from projects the attacker cannot otherwise access; CVE-2026-15831 (CVSS 4.3, EE-only, affects 19.1+) is a flawed security-token-generation issue in Duo Workflows letting an authenticated user bypass administrator-configured AI tool-governance policies; CVE-2026-14351 (CVSS 4.3, CWE-1230, affects 8.8+) exposes confidential issue titles through merge-request-title-generation metadata; CVE-2026-4672 (CVSS 4.3, affects 18.4+) is an access-control flaw letting a Guest-role user view Pipeline Test Report contents they are not authorized to see, reported by researcher rogerace via HackerOne; and CVE-2025-14562 (CVSS 3.1, affects 10.6+) is an improper-authorization flaw in merge-request collaboration settings that could let a Developer-role user who has been removed from a project retain the ability to commit changes to it.
GitLab's HackerOne public bug-bounty program produced at least four of the reports in this batch, each reserved months before the coordinated July 29 patch release: CVE-2026-4672 (reported by rogerace, reserved 2026-03-23), CVE-2026-6267 (reported by thwin_htet, reserved 2026-04-14), CVE-2026-6336 (reported by 3nvz, reserved 2026-04-15), and CVE-2026-12436 (reported by a0xnirudh, reserved 2026-06-16). GitLab's standard security-release
Weaknesses (CWE)
CWE-201, CWE-915, CWE-770, CWE-367, CWE-522, CWE-79, CWE-1230
References
- GitLab Patches 13 Security Flaws Enabling Data Exposure, CI/CD Tampering and DoS Attacks
- GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash Servers
- GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5
- GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5 - Community Forum
- GitLab Patches 13 Security Flaws Enabling Data Exposure, CI/CD Tampering and DoS Attacks
- GitLab Fixes 13 Security Flaws That Can Leak Data, Alter Pipelines, and Crash Servers
- GitLab Multiple Vulnerabilities
- CVE Record: CVE-2026-6267
- NVD - CVE-2026-6267
- NVD - CVE-2026-12436
- NVD - CVE-2026-15975
- CVE-2026-16553: GitLab EE Information Disclosure Flaw
- CVE-2026-15077: GitLab EE Information Disclosure Flaw
- GitLab Patches Multiple Duo AI, DoS, and Authorization Vulnerabilities
- CVE-2026-6267 record — reservation date, HackerOne credit (thwin_htet)
Detections & IOCs
As of 2026-08-01, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-6267, CVE-2026-12436, CVE-2026-15975, CVE-2026-13113, CVE-2026-16553, CVE-2026-6336, CVE-2026-14341, CVE-2026-3093, CVE-2026-15077, CVE-2026-15831, T1078, T1190, T1195.002, T1059.007, T1098, T1053.005, T1078.004, T1548, T1562.001, T1552