Incorrect authorization in GitLab Enterprise Edition - CVE-2026-86340

 

Incorrect authorization in GitLab Enterprise Edition - CVE-2026-86340

Published: September 11, 2026


Vulnerability identifier: #VU149018
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86340
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass required deployment approvals for protected environments.

The vulnerability exists due to an authorization bypass in protected environment approval rules when deleting the sole approver group or user account. A remote privileged user can delete the sole approver group or user account to bypass required deployment approvals for protected environments.


Affected software

GitLab Enterprise Edition

How to mitigate CVE-2026-86340

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2

External References

Related Security Bulletins