Use of Less Trusted Source in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-92530

 

Use of Less Trusted Source in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-92530

Published: September 23, 2026


Vulnerability identifier: #VU151878
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92530
CWE-ID: CWE-348
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to spoof merge request authorship and attribute content to arbitrary existing users on the target instance.

The vulnerability exists due to improper reliance on ephemeral cache state in Direct Transfer import user mapping when processing Direct Transfer imports. A remote user can perform a Direct Transfer import to spoof merge request authorship and attribute content to arbitrary existing users on the target instance.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

How to mitigate CVE-2026-92530

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1
Gitlab Community Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1

External References

Related Security Bulletins