CVE-2026-13210: GitLab
High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables outside their intended environment scope due to improper input validation in the environment scope pattern matcher.
Affected products
- GitLab GitLab: from 15.7.0, before 19.1.8 (fixed in 19.1.8); from 19.2.0, before 19.2.6 (fixed in 19.2.6); from 19.3.0, before 19.3.2 (fixed in 19.3.2)
Published 2026-09-15. Last modified 2026-09-28.