CVE-2026-0934
Received Received - Intake
Authenticated User Access Bypass in GitLab EE

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: GitLab Inc.

Description
GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations despite CI/CD visibility being disabled for the project.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
gitlab gitlab_enterprise_edition From 17.9|end_excluding=18.11.6 (inc)
gitlab gitlab_enterprise_edition From 19.0|end_excluding=19.0.3 (inc)
gitlab gitlab_enterprise_edition From 19.1|end_excluding=19.1.1 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-0934 is an Improper Access Control vulnerability in GitLab Enterprise Edition (EE). It allows an authenticated user who has custom role permissions to view, create, or delete protected environment configurations even when CI/CD visibility is disabled for the project.

This issue affects GitLab EE versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1.

Compliance Impact

The provided information does not specify how this vulnerability impacts compliance with common standards and regulations such as GDPR or HIPAA.

Impact Analysis

This vulnerability could allow an authenticated user with certain custom role permissions to improperly access and modify protected environment configurations in GitLab projects.

Such unauthorized access could lead to unintended changes or exposure of sensitive deployment environments, potentially impacting the integrity and confidentiality of the CI/CD pipeline.

Mitigation Strategies

To mitigate this vulnerability, users are advised to upgrade GitLab Enterprise Edition to the latest patched versions.

  • Upgrade to GitLab EE version 18.11.6 or later if using version 17.9 up to before 18.11.6.
  • Upgrade to GitLab EE version 19.0.3 or later if using version 19.0 up to before 19.0.3.
  • Upgrade to GitLab EE version 19.1.1 or later if using version 19.1 up to before 19.1.1.
Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0934. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart