What is CVE-2026-14341?
A vulnerability (CVE-2026-14341) in GitLab CE/EE allowed an authenticated user with the Maintainer role to modify protected branch configurations under certain conditions due to improper authorization. This issue affects all versions starting from 12.8 and has been remediated in versions 19.0.5, 19.1.3, and 19.2.1. Affected users should immediately upgrade to the patched versions to mitigate the risk.
Azərbaycanca: GitLab CE/EE məhsulunda aşkarlanan CVE-2026-14341 boşluğu, müəyyən şərtlər altında Maintainer roluna malik autentifikasiya olunmuş istifadəçinin səlahiyyət yoxlamasındakı zəiflik səbəbilə qorunan branch konfiqurasiyasını dəyişməsinə imkan verirdi. Bu boşluq 12.8-dən etibarən bir çox versiyaya təsir edir və təhlükəsizlik yeniləmələri ilə aradan qaldırılıb. Təsirə məruz qalmamaq üçün GitLab instansiyalarınızı dərhal 19.0.5, 19.1.3, 19.2.1 və ya daha yuxarı versiyalara yeniləməlisiniz.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: GitLab
FAQ2
What role must a malicious user have to exploit CVE-2026-14341?
To exploit this vulnerability, a user must be authenticated with the Maintainer role.
Starting from which GitLab version did this security issue appear?
The CVE-2026-14341 vulnerability affects all versions starting from 12.8.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.