Gitlab · Gitlab Ce/Ee · CVE-2026-16794
**Name of the Vulnerable Software and Affected Versions**
GitLab EE versions 18.11 through 19.1.7
GitLab EE versions 19.2 through 19.2.5
GitLab EE versions 19.3 through 19.3.1
**Description**
Improper authorization controls on compliance framework management allow an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables within group projects.
**Recommendations**
Update to version 19.1.8.
Update to version 19.2.6.
Update to version 19.3.2.