PT-2026-52194 · Gitlab · Gitlab Ce/Ee
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab EE versions 17.9 through 18.11.5
GitLab EE versions 19.0 through 19.0.2
GitLab EE versions 19.1 through 19.1.0
Description
An incorrect authorization issue exists where an authenticated user with custom role permissions can view, create, or delete protected environment configurations. This occurs even when CI/CD visibility is disabled for the project. Protected environments are used to control deployments to sensitive areas such as production or staging.
Recommendations
Update versions 17.9 through 18.11.5 to 18.11.6.
Update versions 19.0 through 19.0.2 to 19.0.3.
Update versions 19.1 through 19.1.0 to 19.1.1.
Review custom role permissions and monitor protected environment settings for unexpected changes.
Exploit
Fix
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab Ce/Ee