medium · CVSS v3 5
CVE-2026-86340
CVE-2026-86340 exposes a flaw in the deployment gate logic of protected environments. High‑privileged users can delete the sole approver (us
Overview
CVE-2026-86340 exposes a flaw in the deployment gate logic of protected environments. High‑privileged users can delete the sole approver (user or group) and bypass the required multi‑party approval process, allowing unauthorized deployments.
Description
The vulnerability exists due to a structural flaw in deployment gate logic for protected environments. High-privileged users can entirely bypass mandated multi-party deployment approval configurations by simply deleting the sole individual user or user group assigned as the approver rule.
Impact
Defenders lose control over the integrity of deployment approvals. Unauthorized changes can be made to production or sensitive environments, potentially compromising confidentiality, integrity, and availability of deployed services.
Remediation
['Ensure that approval rules require at least two distinct approvers (users or groups).', 'Implement role‑based access controls that restrict deletion of approver assignments to users with no deployment privileges.', 'Enable audit logging for all changes to approval configurations and monitor for privileged deletions.', 'Apply vendor patches or configuration updates that enforce multi‑party approval checks.', 'Regularly review and harden deployment gate configurations to prevent single‑point approval points.']
Risk context
The vulnerability has a medium CVSS‑v3 score of 5.0. While not critical, it allows privileged users to subvert essential security controls, making it a high‑priority concern for environments that rely on strict deployment approvals.
Affected products
- Deployment Gate System
- Protected Environment Manager
- Approval Workflow Engine
- CI/CD Platform
- Infrastructure‑as‑Code Tool
- Release Automation Suite
- Configuration Management System
- Deployment Orchestration Platform
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 5
- CVSS v4
- —
- EPSS
- —