Unrated severityOSV Advisory· Published Feb 2, 2026· Updated Feb 2, 2026
Missing Authorization in GitLab
CVE-2026-1751
Description
A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/2980839mitretechnical-descriptionexploitpermissions-required
- gitlab.com/gitlab-org/gitlab/-/issues/519340mitreissue-trackingpermissions-required
News mentions
0No linked articles in our index yet.