Improper Encoding or Escaping of Output in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-9694
Published: June 11, 2026
Gitlab Community Edition
GitLab Enterprise Edition
Detailed vulnerability description
The vulnerability allows a remote user to inject arbitrary content while impersonating the GitLab Support Bot.
The vulnerability exists due to improper neutralization in Service Desk email template processing when handling a specially crafted Service Desk email reply. A remote user can send a specially crafted email reply to inject arbitrary content while impersonating the GitLab Support Bot.
User interaction is required.