Junglewise Threat Intelligence

CVE-2026-0934: GitLab Enterprise Edition improper access control in Protected Environments API

CVE-2026-0934 · Severity: low · CVSS 3.8 · Published 2026-06-25

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition is a platform used by organizations to manage software development and code repositories. A security flaw was found where certain users could view or modify protected environment settings even when those features were supposed to be hidden. This could allow unauthorized individuals to change deployment configurations or view sensitive environment details, potentially disrupting software release processes.

Technical details

An improper access control vulnerability exists in the Protected Environments API of GitLab Enterprise Edition. The flaw allows an authenticated user assigned a custom role to bypass visibility restrictions. Specifically, an attacker can interact with protected environment configurations (viewing, creating, or deleting them) even if CI/CD visibility is explicitly disabled for the project. This issue affects GitLab EE versions 17.9 through 18.11.6, 19.0.x before 19.0.3, and 19.1.x before 19.1.1. Users are advised to upgrade to versions 18.11.6, 19.0.3, or 19.1.1 to remediate the issue.

Affected products

  • GitLab GitLab Enterprise Edition 17.9 to 18.11.6, 19.0 to 19.0.3, 19.1 to 19.1.1

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, and 18.11.6.
  • 2026-06-25: disclosed: NVD published the CVE record.

References

Related threats