CVE-2026-7487
LOW
3,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
Description
AI Translation Available
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request approval rules due to improper authorization checks.
1280
Access Control Check Implemented After Asset is Accessed
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Integrity
Potential Impacts:
Modify Memory
Read Memory
Modify Application Data
Read Application Data
Gain Privileges Or Assume Identity
Bypass Protection Mechanism
Applicable Platforms
Languages:
Verilog, VHDL, Not Language-Specific
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/
https://gitlab.com/gitlab-org/gitlab/-/work_items/598657
https://hackerone.com/reports/3669140