What is CVE-2026-15831?
This vulnerability affects GitLab Enterprise Edition (EE), where an authenticated user could bypass administrator-configured tool governance policies due to improper authorization enforcement during token operations. Affected versions include all from 19.1 before 19.1.3 and 19.2 before 19.2.1, and immediate update to the patched versions is strongly recommended.
Azərbaycanca: Bu boşluq GitLab Enterprise Edition (EE) versiyalarına təsir edir və autentifikasiya olunmuş istifadəçiyə token əməliyyatları zamanı səhv icazə yoxlaması səbəbindən administrator tərəfindən təyin edilmiş alət idarəetmə siyasətlərini keçməyə imkan verirdi. Təsirə məruz qalan versiyalar 19.1-dən 19.1.3-ə və 19.2-dən 19.2.1-ə qədərdir; düzəliş üçün dərhal göstərilən təhlükəsizlik yeniləmələrinə keçmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: GitLab
FAQ2
Which GitLab versions are affected by CVE-2026-15831?
This vulnerability affects all GitLab Enterprise Edition (EE) versions from 19.1 before 19.1.3 and from 19.2 before 19.2.1.
What security mechanism can be bypassed by exploiting CVE-2026-15831?
This vulnerability allows an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token operations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.