Access Control Flaw in GitLab Affects Environment Deployment Approvals
CVE-2026-86341

4.4MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-86341?

GitLab has addressed a serious access control issue within its EE product, impacting versions from 17.1 to 19.3.2. The vulnerability occurs when an authenticated user possessing Owner or Maintainer permissions can inadvertently disable deployment approval requirements for protected environments. This flaw allows unauthorized deployments, risking the integrity of production environments due to inadequate access control checks executed post-modification of the protected resource. Immediate action is necessary for users to update to the latest version to safeguard against potential exploitation.

Affected Version(s)

GitLab 17.1 < 19.1.8

GitLab 19.2 < 19.2.6

GitLab 19.3 < 19.3.2

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team member Peter Arts
.