Access Control Flaw in GitLab Affects Environment Deployment Approvals
CVE-2026-86341
4.4MEDIUM
What is CVE-2026-86341?
GitLab has addressed a serious access control issue within its EE product, impacting versions from 17.1 to 19.3.2. The vulnerability occurs when an authenticated user possessing Owner or Maintainer permissions can inadvertently disable deployment approval requirements for protected environments. This flaw allows unauthorized deployments, risking the integrity of production environments due to inadequate access control checks executed post-modification of the protected resource. Immediate action is necessary for users to update to the latest version to safeguard against potential exploitation.
Affected Version(s)
GitLab 17.1 < 19.1.8
GitLab 19.2 < 19.2.6
GitLab 19.3 < 19.3.2
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability has been discovered internally by GitLab team member Peter Arts