---
id: CVE-2026-107589
title: >-
  Insufficient job validation for service accounts in Jacamar CI prior to
  v0.30.0 allows authenticated CI users to generate arbitrary account names.
summary: >-
  Insufficient job validation for service accounts in Jacamar CI prior to
  v0.30.0 allows authenticated CI users to generate arbitrary account names.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:L'
cwe:
  - CWE-290
vendor: Jacamar CI
product: Jacamar CI
affected:
  - jacamar_ci < 0.30.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:02:43.860'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107589'
references:
  - url: 'https://ecp-ci.gitlab.io/docs/releasenotes/jacamar/jacamar_0.30.0.html'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T15:49:37.991Z'
---

## Overview

Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
