Use of Less Trusted Source in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-92530
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to spoof merge request authorship and attribute content to arbitrary existing users on the target instance.
The vulnerability exists due to improper reliance on ephemeral cache state in Direct Transfer import user mapping when processing Direct Transfer imports. A remote user can perform a Direct Transfer import to spoof merge request authorship and attribute content to arbitrary existing users on the target instance.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-92530
Gitlab Community Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1