Description
GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks.
Published: 2026-05-14
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in the GitLab Enterprise Edition that allows an authenticated user with Maintainer permissions to modify or delete project approval rules when instance‑level approval rule editing prevention is enabled. This flaw can be used to alter project governance parameters, potentially undermining compliance requirements or escalating privileges within the repository environment. It is classified as CWE‑862, an authorization failure weakness.

Affected Systems

Affected vendors and products include GitLab: GitLab, specifically all Enterprise Edition instances from version 16.10 up to, but not including, 18.9.7, 18.10.6, and 18.11.3. The vulnerability does not impact Community Edition releases or other GitLab components, and the version bounds are clearly specified in the vendor remediation guidance.

Risk and Exploitability

The CVSS score of 2.7 marks the issue as low severity, and the EPSS score is not available, indicating limited publicly known exploitation data. The flaw is not listed in the CISA KEV catalog. An attacker must be authenticated and hold Maintainer rights, making the attack vector internal and requiring prior access to the GitLab instance. While the potential impact involves unauthorized project rule modifications, the low CVSS and absence of public exploits suggest a moderate risk profile that still warrants timely remediation.

Generated by OpenCVE AI on May 14, 2026 at 07:23 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.9.7, 18.10.6, 18.11.3 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab Enterprise Edition to version 18.9.7, 18.10.6, 18.11.3 or later, which removes the missing authorization check
  • If an immediate upgrade is not feasible, disable instance‑level approval rule editing prevention in the project settings to prevent Maintainers from modifying or deleting approval rules
  • Review and reduce the scope of Maintainer permissions for users who do not need to edit approval rules, or enforce stricter role‑based access controls

Generated by OpenCVE AI on May 14, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 16 May 2026 03:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Thu, 14 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 May 2026 06:00:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that when instance-level approval rule editing prevention was enabled, could have allowed an authenticated user with Maintainer permissions to modify or delete project approval rules due to missing authorization checks.
Title Missing Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-862
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-05-14T13:07:17.299Z

Reserved: 2026-02-20T19:33:13.460Z

Link: CVE-2026-2900

cve-icon Vulnrichment

Updated: 2026-05-14T13:07:13.558Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-14T06:16:21.803

Modified: 2026-05-16T03:36:41.993

Link: CVE-2026-2900

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-14T07:30:06Z

Weaknesses