What is CVE-2026-12436?
CVE-2026-12436 is a vulnerability in GitLab CE/EE that could allow an authenticated user to modify another user's CI/CD configuration under certain conditions due to improper validation. Affected versions include all from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Users should update to the latest patched versions immediately.
Azərbaycanca: CVE-2026-12436, GitLab CE/EE platformasında aşkarlanmış boşluqdur. Bu problem, autentifikasiya olunmuş istifadəçinin müəyyən şərtlər altında başqa bir istifadəçiyə məxsus CI/CD konfiqurasiyasını dəyişməsinə imkan verə bilərdi. İstifadəçilərə versiyalarını 19.0.5, 19.1.3 və ya 19.2.1 səviyyəsinə yeniləmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: GitLab
FAQ2
What is CVE-2026-12436?
CVE-2026-12436 is a vulnerability in GitLab CE/EE that could allow an authenticated user to modify another user's CI/CD configuration under certain conditions due to improper validation.
Which versions are affected by CVE-2026-12436?
This vulnerability affects all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1. Users are advised to update to at least versions 19.0.5, 19.1.3, or 19.2.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.