CVE-2026-1752
Last modified
CVE-2026-1752 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected environment settings due to improper authorization checks in the API.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 11.3.0, < 18.8.9 |
| Gitlab | Gitlab | >= 18.9.0, < 18.9.5 |
| Gitlab | Gitlab | >= 18.10.0, < 18.10.3 |
References
- https://about.gitlab.com/releases/2026/04/08/patch-release-gitlab-18-10-3-released/Release Notes, Vendor Advisory
- https://hackerone.com/reports/3533545Permissions Required
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-1752?
How severe is CVE-2026-1752?
How do I fix CVE-2026-1752?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-17512A vulnerability has been found in ggml-org whisper.cpp 1.8.4…3.3
- CVE-2026-17513A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. …3.3
- CVE-2026-17514A vulnerability was determined in ZJONSSON node-unzipper up …5.3
- CVE-2026-17515The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listi…4.3
- CVE-2026-17517The Content Views WordPress plugin before 4.5.1.2 does not …5.3
- CVE-2026-17519Rejected reason: This is rejected.
- CVE-2026-17520The Newsletters WordPress plugin before 4.17 does not genera…4.8
- CVE-2026-17522The Newsletters WordPress plugin before 4.17 does not perfor…5.4
- CVE-2026-17523In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-17524Versions of the package zip-lib before 1.1.0 are vulnerable …8.7
- CVE-2026-17526Keycloak is an open-source identity and access management so…7.2
- CVE-2026-17527In containerized-data-importer (CDI), the aggregated cdi.kub…7.7
Are you affected by CVE-2026-1752?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
