PT-2026-52194 · Gitlab · Gitlab Ce/Ee

·

CVE-2026-0934

·

Published

2026-06-24

·

Updated

2026-06-29

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 17.9 through 18.11.5 GitLab EE versions 19.0 through 19.0.2 GitLab EE versions 19.1 through 19.1.0
Description An incorrect authorization issue exists where an authenticated user with custom role permissions can view, create, or delete protected environment configurations. This occurs even when CI/CD visibility is disabled for the project. Protected environments are used to control deployments to sensitive areas such as production or staging.
Recommendations Update versions 17.9 through 18.11.5 to 18.11.6. Update versions 19.0 through 19.0.2 to 19.0.3. Update versions 19.1 through 19.1.0 to 19.1.1. Review custom role permissions and monitor protected environment settings for unexpected changes.

Exploit

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09072
BIT-GITLAB-2026-0934
CVE-2026-0934

Affected Products

Gitlab Ce/Ee