SB2026092388 - Multiple vulnerabilities in GitLab CE/EE
Published: September 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-10518)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read private security policy content they are not authorized to access.
The vulnerability exists due to improper authorization enforcement in the GraphQL memberRoles dependentSecurityPolicies resolver when resolving security policies. A remote user can query the resolver to read private security policy content they are not authorized to access.
Exploitation requires guest-level permissions.
2) Integer overflow (CVE-ID: CVE-2026-93577)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code on the GitLab server.
The vulnerability exists due to an integer overflow in the regular expression compiler when compiling a specially crafted regular expression in a CI/CD configuration. A remote user can submit a specially crafted regular expression to execute arbitrary code on the GitLab server.
3) Cross-site scripting (CVE-ID: CVE-2026-84739)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser session.
The vulnerability exists due to improper sanitization of path components in the merge request diff viewer when rendering merge request diffs. A remote user can provide crafted path components to execute arbitrary JavaScript in another user's browser session.
User interaction is required.
4) Missing Authorization (CVE-ID: CVE-2026-92470)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access sensitive CI/CD variable values from debug-mode job traces.
The vulnerability exists due to missing authorization checks in the Duo AI troubleshooting feature when accessing debug-mode job traces. A remote user can access debug-mode job traces to access sensitive CI/CD variable values from debug-mode job traces.
5) Incorrect authorization (CVE-ID: CVE-2026-92874)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform actions beyond the intended scope of an MCP-scoped token.
The vulnerability exists due to improper authorization checks in MCP API scope enforcement when processing requests with an MCP-scoped token. A remote user can use an MCP-scoped token to perform actions beyond the intended scope of an MCP-scoped token.
6) Use of Less Trusted Source (CVE-ID: CVE-2026-92530)
CWE-ID: CWE-348 - Use of Less Trusted Source
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to spoof merge request authorship and attribute content to arbitrary existing users on the target instance.
The vulnerability exists due to improper reliance on ephemeral cache state in Direct Transfer import user mapping when processing Direct Transfer imports. A remote user can perform a Direct Transfer import to spoof merge request authorship and attribute content to arbitrary existing users on the target instance.
7) Missing Authorization (CVE-ID: CVE-2026-8937)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read private child issue contents from projects they cannot access.
The vulnerability exists due to missing authorization checks in the Epic Issues REST API when accessing linked work items within visible epics. A remote user can access linked work items within visible epics to read private child issue contents from projects they cannot access.
Disclosed content includes issue titles and descriptions.
8) Incorrect authorization (CVE-ID: CVE-2026-92529)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control.
The vulnerability exists due to improper authorization checks in Duo Workflow Service token governance enforcement when processing workflows. A remote user can process a workflow to bypass admin-configured AI tool governance controls for workflows in namespaces they do not control.
Exploitation requires developer-role permissions.
9) Double free (CVE-ID: CVE-2026-89078)
CWE-ID: CWE-415 - Double Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code on the GitLab server.
The vulnerability exists due to a double free in the regular expression parser when parsing a specially crafted regular expression in a CI/CD configuration. A remote user can submit a specially crafted regular expression to execute arbitrary code on the GitLab server.
10) Missing Authorization (CVE-ID: CVE-2026-4523)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read CI/CD job trace contents containing sensitive variable values.
The vulnerability exists due to improper authorization enforcement in the GraphQL CI job trace API when accessing CI/CD job traces. A remote attacker can access CI/CD job traces to read CI/CD job trace contents containing sensitive variable values.
11) Race condition (CVE-ID: CVE-2026-92628)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to receive search results under an incorrect user context.
The vulnerability exists due to a race condition in the MCP gitlab_search tool when handling concurrent searches. A remote user can perform searches during a race condition to receive search results under an incorrect user context.
Remediation
Install update from vendor's website.
References
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-10518---improper-access-control-issue-in-graphql-memberroles-dependentsecuritypolicies-resolver-impacts-gitlab-ee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-93577---integer-overflow-issue-in-regular-expression-compiler-impacts-gitlab-ceee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-84739---cross-site-scripting-issue-in-merge-request-diff-viewer-impacts-gitlab-ceee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-92470---missing-authorization-issue-in-duo-ai-job-troubleshooting-feature-impacts-gitlab-ee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-92874---incorrect-authorization-issue-in-mcp-api-scope-enforcement-impacts-gitlab-ceee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-92530---use-of-less-trusted-source-issue-in-direct-transfer-import-user-mapping-impacts-gitlab-ceee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-8937---missing-authorization-issue-in-epic-issues-rest-api-impacts-gitlab-ceee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-92529---incorrect-authorization-issue-in-duo-workflow-service-token-governance-enforcement-impacts-gitlab-ee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-89078---double-free-issue-in-regular-expression-parser-impacts-gitlab-ceee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-4523---missing-authorization-issue-in-graphql-ci-job-trace-api-impacts-gitlab-ceee
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/#cve-2026-92628---race-condition-issue-in-mcp-gitlab_search-tool-impacts-gitlab-ceee