Threat Advisory

GitLab Flaws Let Attackers Read and Execute Code

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting GitLab versions The flaws affect a range of releases before the fixed builds have been identified in GitLab Community and Enterprise Editions, affecting versions prior to 19.2.2, 19.1.4, and 19.0.6. The most severe are high-rated cross-site scripting bugs with a CVSS score of 8.7. GitLab reports no known exploitation.

CVE-2026-15217 (CVSS 8.7 — High): Two cross-site scripting bugs in Analytics Dashboards allow an attacker to plant a script through user-controlled values before rendering them, which can run when a victim loads the page.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting GitLab versions The flaws affect a range of releases before the fixed builds have been identified in GitLab Community and Enterprise Editions, affecting versions prior to 19.2.2, 19.1.4, and 19.0.6. The most severe are high-rated cross-site scripting bugs with a CVSS score of 8.7. GitLab reports no known exploitation.

CVE-2026-15217 (CVSS 8.7 — High): Two cross-site scripting bugs in Analytics Dashboards allow an attacker to plant a script through user-controlled values before rendering them, which can run when a victim loads the page.[emaillocker id="1283"]

CVE-2026-15216 (CVSS 8.7 — High): Another cross-site scripting bug in Analytics Dashboards allows an attacker to plant a script through user-controlled values before rendering them, which can run when a victim loads the page.

CVE-2026-15423 (CVSS 8.5 — High): A developer-role user can run pipelines on a protected branch without push rights due to missing authorization checks across APIs.

CVE-2026-19228 (CVSS 8.5 — Medium): An attacker can exploit missing authorization checks across APIs, allowing unauthorized access to sensitive data.

CVE-2026-16627 (CVSS 7.7 — Medium): A vulnerability in CI/CD pipeline abuse allows an attacker to manipulate the pipeline without proper authorization.

CVE-2026-16494 (CVSS 7.1 — Medium): Missing authorization checks across APIs allow unauthorized access to sensitive data.

CVE-2026-7427 (CVSS 5.3 — Low): A vulnerability in CI/CD pipeline abuse allows an attacker to manipulate the pipeline without proper authorization.

CVE-2026-6821 (CVSS 4.3 — Low): Missing authorization checks across APIs allow unauthorized access to sensitive data. These vulnerabilities collectively present a significant risk, particularly for teams that rely on GitLab for source code, secrets, and CI/CD pipelines. Administrators should apply the latest security updates now to mitigate potential threats. These vulnerabilities collectively present a significant risk, particularly for teams that rely on GitLab for source code, secrets, and CI/CD pipelines.

These vulnerabilities collectively present a significant risk, particularly for teams that rely on GitLab for source code, secrets, and CI/CD pipelines.

RECOMMENDATION:

We recommend you to update GitLab to version 19.2.2, 19.1.4, or 19.0.6.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu