GitLabCVE-2026-14341
GitLab: improper authorization
Medium4.9CVE-2026-14341 · Published Jul 29, 2026 · updated Aug 3, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API endpoint.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| GitLab Product | >= 12.8, < 19.0.5 | 19.0.5 |
| >= 19.1, < 19.1.3 | 19.1.3 | |
| >= 19.2, < 19.2.1 | 19.2.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More GitLab advisories
All GitLab| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | GitLab: information disclosure | High8.5 | 19.0.5+2 more |
| Jul 29 | GitLab: missing authorization | Medium5.3 | 19.0.5+2 more |
| Jul 29 | GitLab: cross-site scripting | Medium4.7 | 19.0.5+2 more |
| Jul 29 | GitLab: improper access control | Medium4.3 | 19.0.5+2 more |
| Jul 29 | GitLab: denial of service | High7.5 | 19.0.5+2 more |
| Jul 29 | GitLab: information disclosure | Medium5.4 | 19.0.5+2 more |