SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14341

MEDIUM · CVSS 4.9 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

GitLab is vulnerable across multiple versions, where an authenticated user with a Maintainer role can exploit improper authorization in a project's API endpoint to modify protected branch configurations. This could lead to unauthorized changes in critical project settings, potentially impacting code integrity and security. Organizations using affected versions of GitLab should prioritize remediation to mitigate risks associated with this vulnerability.

CVE
CVE-2026-14341
Severity
MEDIUM
CVSS
4.9
EPSS
0.33%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to improper authorization in a projects API endpoint.

Related CVEs

Other vulnerabilities affecting the same vendor(s)