Cross-site request forgery in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-4922
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute GraphQL mutations on behalf of authenticated users.
The vulnerability exists due to insufficient CSRF protection in GraphQL API when handling GraphQL mutation requests. A remote attacker can send a specially crafted request to execute GraphQL mutations on behalf of authenticated users.
User interaction is required.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-4922
GitLab Enterprise Edition - addressed in versions 18.9.6, 18.10.4, 18.11.1