Intel

AIKIDO-2026-630586

gitlab-ce is vulnerable to Authorization Bypass

Authorization BypassCVE-2026-86340 Published 3 days ago

44

Medium Risk

This Affects:

OSgitlab-ce
17.1.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

Protected environment deployment approvals can be bypassed by deleting the sole approver group or user account. An authenticated attacker can then deploy to protected environments without the required approvals. The fix keeps approval requirements enforceable when the last approver is removed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use protected environments with deployment approvals.

Background info

gitlab-ce is vulnerable to Authorization Bypass in versions 17.1.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform