CVE-2026-1752 is an authorization bypass vulnerability in GitLab Enterprise Edition affecting versions 11.3 through 18.10.2 that allows authenticated developers to modify protected environment settings through improper API authorization checks. The vulnerability impacts multiple release lines including 18.8 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3. The vulnerability has a CVSS score of 4.3 (Medium severity) with network-based attack vector, low complexity, and low privilege requirements. The impact is limited to integrity compromise with no confidentiality or availability impact, indicating an attacker could modify protected environment configurations but cannot access sensitive data or cause service disruption. There is currently no evidence of active exploitation in the wild. The vulnerability is not tracked in the Known Exploited Vulnerabilities catalog, has extremely low EPSS probability of exploitation (0.0001), and remains inactive on public exploit lists. However, organizations running affected GitLab EE versions should apply available patches to maintain proper access controls over environment protections.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.3.0, < 18.8.9CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.9.0, < 18.9.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.10.0, < 18.10.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.10, < 18.10.3CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 11.3, < 18.8.9CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.