Gitlab · Gitlab Ce/Ee · CVE-2026-0934
**Name of the Vulnerable Software and Affected Versions**
GitLab EE versions 17.9 through 18.11.5
GitLab EE versions 19.0 through 19.0.2
GitLab EE versions 19.1 through 19.1.0
**Description**
An incorrect authorization issue exists where an authenticated user with custom role permissions can view, create, or delete protected environment configurations. This occurs even when CI/CD visibility is disabled for the project. Protected environments are used to control deployments to sensitive areas such as production or staging.
**Recommendations**
Update versions 17.9 through 18.11.5 to 18.11.6.
Update versions 19.0 through 19.0.2 to 19.0.3.
Update versions 19.1 through 19.1.0 to 19.1.1.
Review custom role permissions and monitor protected environment settings for unexpected changes.