Multiple security vulnerabilities affecting GitLab versions The flaws affect a range of releases before the fixed builds have been identified in GitLab Community and Enterprise Editions, affecting versions prior to 19.2.2, 19.1.4, and 19.0.6. The most severe are high-rated cross-site scripting bugs with a CVSS score of 8.7. GitLab reports no known exploitation.
CVE-2026-15217 (CVSS 8.7 — High): Two cross-site scripting bugs in Analytics Dashboards allow an attacker to plant a script through user-controlled values before rendering them, which can run when a victim loads the page.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting GitLab versions The flaws affect a range of releases before the fixed builds have been identified in GitLab Community and Enterprise Editions, affecting versions prior to 19.2.2, 19.1.4, and 19.0.6. The most severe are high-rated cross-site scripting bugs with a CVSS score of 8.7. GitLab reports no known exploitation.
CVE-2026-15217 (CVSS 8.7 — High): Two cross-site scripting bugs in Analytics Dashboards allow an attacker to plant a script through user-controlled values before rendering them, which can run when a victim loads the page.[emaillocker id="1283"]
CVE-2026-15216 (CVSS 8.7 — High): Another cross-site scripting bug in Analytics Dashboards allows an attacker to plant a script through user-controlled values before rendering them, which can run when a victim loads the page.
CVE-2026-15423 (CVSS 8.5 — High): A developer-role user can run pipelines on a protected branch without push rights due to missing authorization checks across APIs.
CVE-2026-19228 (CVSS 8.5 — Medium): An attacker can exploit missing authorization checks across APIs, allowing unauthorized access to sensitive data.
CVE-2026-16627 (CVSS 7.7 — Medium): A vulnerability in CI/CD pipeline abuse allows an attacker to manipulate the pipeline without proper authorization.
CVE-2026-16494 (CVSS 7.1 — Medium): Missing authorization checks across APIs allow unauthorized access to sensitive data.
CVE-2026-7427 (CVSS 5.3 — Low): A vulnerability in CI/CD pipeline abuse allows an attacker to manipulate the pipeline without proper authorization.
CVE-2026-6821 (CVSS 4.3 — Low): Missing authorization checks across APIs allow unauthorized access to sensitive data. These vulnerabilities collectively present a significant risk, particularly for teams that rely on GitLab for source code, secrets, and CI/CD pipelines. Administrators should apply the latest security updates now to mitigate potential threats. These vulnerabilities collectively present a significant risk, particularly for teams that rely on GitLab for source code, secrets, and CI/CD pipelines.
These vulnerabilities collectively present a significant risk, particularly for teams that rely on GitLab for source code, secrets, and CI/CD pipelines.
We recommend you to update GitLab to version 19.2.2, 19.1.4, or 19.0.6.
The following reports contain further technical details:
[/emaillocker]