Incorrect authorization in GitLab Enterprise Edition - CVE-2026-86340
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to bypass required deployment approvals for protected environments.
The vulnerability exists due to an authorization bypass in protected environment approval rules when deleting the sole approver group or user account. A remote privileged user can delete the sole approver group or user account to bypass required deployment approvals for protected environments.