CVE-2026-1747 - Authentication Bypass Using an Alternate Path or Channel in GitLab

CVE-2026-1747 - Authentication Bypass Using an Alternate Path or Channel in GitLab

CVE ID : CVE-2026-1747 Published : Feb. 25, 2026, 8:04 p.m. | 52 minutes ago Description : GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Feb. 25, 2026
Affected Product: GitLab