CVE-2026-86341: GitLab
Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.
GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment deployment approval requirements, allowing unapproved deployments to reach production, due to improper access control checks performed after the protected resource was modified.
Affected products
- GitLab GitLab: from 17.1.0, before 19.1.8 (fixed in 19.1.8); from 19.2.0, before 19.2.6 (fixed in 19.2.6); from 19.3.0, before 19.3.2 (fixed in 19.3.2)
Published 2026-09-16. Last modified 2026-09-28.