CVE-2026-15831
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-1270
- Published
- 2026-07-29
- Last modified
- 2026-07-29
Affected products
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-19636 — Insuffucient Protections Lead to Brute Force
- CVE-2026-54593 — Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
- CVE-2026-49499 — Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect...
- CVE-2023-32188 — JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
- CVE-2023-22644 — JWT token compromise can allow malicious actions including Remote Code Execution (RCE)
- CVE-2023-2882 — Privilege Escalation in CBOT's Chatbot
- CVE-2022-31122 — Wire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creation