Intel

AIKIDO-2026-894291

gitlab-ce is vulnerable to Improper Access Control

Improper Access ControlCVE-2026-86341 Published 3 days ago

44

Medium Risk

This Affects:

OSgitlab-ce
17.1.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

Protected environment approval checks can run after the protected resource has already been modified. An authenticated Owner or Maintainer can silently disable deployment approval requirements so unapproved deployments reach production. The fix performs access control before modifying protected environment approval state.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and use protected environments with deployment approvals.

Background info

gitlab-ce is vulnerable to Improper Access Control in versions 17.1.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform