---
id: CVE-2026-86341
title: >-
  GitLab has remediated an issue in GitLab EE affecting all versions from 17.1
  before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain
  conditions, an authenticated user with Owner or Maintainer permissions could
  have …
summary: >-
  GitLab has remediated an issue in GitLab EE affecting all versions from 17.1
  before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain
  conditions, an authenticated user with Owner or Maintainer permissions could
  have …
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-1280
vendor: GitLab
product: GitLab
affected:
  - GitLab >= 17.1 < 19.1.8
  - GitLab >= 19.2 < 19.2.6
  - GitLab >= 19.3 < 19.3.2
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:23:34.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86341'
references:
  - url: >-
      https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
    label: cve@gitlab.com
  - url: 'https://gitlab.com/gitlab-org/gitlab/-/work_items/600088'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T14:53:00.578372Z'
ingestedAt: '2026-09-16T08:52:29.588Z'
epss: 0.00318
epssPercentile: 0.24929
---

## Overview

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment deployment approval requirements, allowing unapproved deployments to reach production, due to improper access control checks performed after the protected resource was modified.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
