Junglewise Threat Intelligence

CVE-2026-14341: GitLab CE/EE improper authorization in protected branch configuration

CVE-2026-14341 · Severity: medium · CVSS 4.9 · Published 2026-07-29

Technologies: GitLab Enterprise Edition (EE), GitLab Community Edition (CE). Vendors: GitLab.

Executive brief

GitLab, a platform for software development and version control, has addressed a security flaw that could allow certain authorized users to bypass restrictions on protected code branches. Specifically, a user with the 'Maintainer' role could modify branch configurations they should not have access to change. This could lead to unauthorized code changes or the bypassing of established development workflows and security controls.

Technical details

An improper authorization vulnerability (CWE-862) exists in the GitLab projects API endpoint. The flaw allows an authenticated user with 'Maintainer' privileges to modify protected branch configurations under specific conditions, bypassing intended access controls. The issue affects GitLab CE/EE versions 12.8 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. Attackers require network access and high-level (Maintainer) privileges to exploit this vulnerability. GitLab has released patches in versions 19.0.5, 19.1.3, and 19.2.1 to address the issue.

Affected products

  • GitLab GitLab Community Edition (CE) 12.8 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1
  • GitLab GitLab Enterprise Edition (EE) 12.8 to 19.0.5, 19.1 to 19.1.3, 19.2 to 19.2.1

Timeline

  • 2026-07-29: patched: GitLab released versions 19.2.1, 19.1.3, and 19.0.5.
  • 2026-07-29: advisory: NVD and GitLab published the vulnerability details.

References