Improper access control in GitLab Enterprise Edition - CVE-2026-86341
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to perform unapproved deployments to production.
The vulnerability exists due to improper access control checks in protected environment approval rules when modifying protected resources. A remote privileged user can disable protected environment deployment approval requirements to perform unapproved deployments to production.