CVE-2026-12436
GitLab · GitLab CE/EE
GitLab CE/EE is vulnerable to an improper control of object attributes, allowing an authenticated user to perform unauthorized modifications.
Executive summary
A vulnerability in GitLab CE/EE allows authenticated users to manipulate object attributes, potentially leading to unauthorized system changes or privilege escalation.
Vulnerability
This issue is an improper control of dynamically determined object attributes (CWE-915). It requires an authenticated user to successfully exploit the flaw.
Business impact
The vulnerability carries a CVSS score of 8.4, reflecting a high severity risk. Successful exploitation could allow a malicious actor to modify system objects, potentially resulting in unauthorized administrative access, data integrity loss, or significant service disruption within the GitLab environment.
Remediation
Immediate Action: Upgrade GitLab installations to versions 19.0.5, 19.1.3, 19.2.1, or later immediately.
Proactive Monitoring: Review audit logs for suspicious configuration changes or unexpected modifications to project or user attributes.
Compensating Controls: Implement strict access control lists and principle of least privilege to limit the impact of compromised accounts until patching is complete.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability, administrators should prioritize updating their GitLab instances. Applying the vendor-supplied patches is the only reliable way to neutralize this risk.