CVE-2026-1747

G

itLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*

History

28 Feb 2026, 01:05

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
References () https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/ - () https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-released/ - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/588385 - () https://gitlab.com/gitlab-org/gitlab/-/issues/588385 - Broken Link
References () https://hackerone.com/reports/3533088 - () https://hackerone.com/reports/3533088 - Permissions Required
CPE cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.9.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
CWE NVD-CWE-noinfo

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) GitLab ha remediado un problema en GitLab EE que afectaba a todas las versiones desde la 17.11 anteriores a la 18.7.5, la 18.8 anteriores a la 18.8.5, y la 18.9 anteriores a la 18.9.1 que, bajo ciertas condiciones, podría haber permitido a usuarios con rol de Desarrollador con privilegios insuficientes realizar modificaciones no autorizadas a paquetes Conan protegidos.

25 Feb 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 21:16

Updated : 2026-02-28 01:05


NVD link : CVE-2026-1747

Mitre link : CVE-2026-1747

CVE.ORG link : CVE-2026-1747


JSON object : View

Products Affected
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

NVD-CWE-noinfo