Gitlab · Gitlab Ce/Ee · CVE-2026-5952
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 17.11 through 18.11.5
GitLab CE/EE versions 19.0 through 19.0.2
GitLab CE/EE versions 19.1 through 19.1.0
**Description**
An incorrect authorization check allows an authenticated user with developer-role permissions to bypass package protection rules. This flaw enables the user to overwrite protected Maven package metadata under certain conditions.
**Recommendations**
Update to version 18.11.6
Update to version 19.0.3
Update to version 19.1.1