Vulnerability Description
GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 17.11.0, < 18.7.5 |
Related Weaknesses (CWE)
References
- https://about.gitlab.com/releases/2026/02/25/patch-release-gitlab-18-9-1-releaseRelease NotesVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/588385Broken Link
- https://hackerone.com/reports/3533088Permissions Required
FAQ
What is CVE-2026-1747?
CVE-2026-1747 is a vulnerability with a CVSS score of 4.3 (MEDIUM). GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-rol...
How severe is CVE-2026-1747?
CVE-2026-1747 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1747?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.