CVE-2026-12436

GitLab · GitLab CE/EE

GitLab CE/EE is vulnerable to an improper control of object attributes, allowing an authenticated user to perform unauthorized modifications.

Executive summary

A vulnerability in GitLab CE/EE allows authenticated users to manipulate object attributes, potentially leading to unauthorized system changes or privilege escalation.

Vulnerability

This issue is an improper control of dynamically determined object attributes (CWE-915). It requires an authenticated user to successfully exploit the flaw.

Business impact

The vulnerability carries a CVSS score of 8.4, reflecting a high severity risk. Successful exploitation could allow a malicious actor to modify system objects, potentially resulting in unauthorized administrative access, data integrity loss, or significant service disruption within the GitLab environment.

Remediation

Immediate Action: Upgrade GitLab installations to versions 19.0.5, 19.1.3, 19.2.1, or later immediately.

Proactive Monitoring: Review audit logs for suspicious configuration changes or unexpected modifications to project or user attributes.

Compensating Controls: Implement strict access control lists and principle of least privilege to limit the impact of compromised accounts until patching is complete.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability, administrators should prioritize updating their GitLab instances. Applying the vendor-supplied patches is the only reliable way to neutralize this risk.