GitLab released 19.0.2, 18.11.5, and 18.10.8 for self-managed Community Edition and Enterprise Edition deployments to fix 11 security vulnerabilities and additional bugs, and urged administrators to upgrade immediately. The advisory says all versions before those releases are affected, while GitLab.com has already been patched and GitLab Dedicated customers do not need to take action. GitLab also warned that the update includes database migrations that may cause downtime on single-node instances, though multi-node environments can use zero-downtime upgrade procedures.
The most severe issue, CVE-2026-6552 (CVSS 8.7), is an improper authorization flaw in GitLab EE's Group SAML identity management that could let an authenticated group Owner take over another group member's account under certain conditions. GitLab also fixed CVE-2026-10087, an Analytics Dashboard cross-site scripting flaw in GitLab EE that could allow an authenticated developer to execute arbitrary client-side code in a victim's browser. The broader patch set addresses additional risks including denial of service in Grape API JSON parsing, SSRF, unauthorized access to confidential data, and other authorization bypasses, and government and vendor advisories have called on organizations to apply the patched versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A public proof-of-concept exploit was published demonstrating remote command execution as the git user on self-managed GitLab by chaining two vulnerabilities in the Oj JSON parser via crafted Jupyter notebook diffs. The researchers said on July 24 they were unaware of in-the-wild exploitation, and the report noted no CVE IDs or CVSS scores had yet been assigned to the two bugs in the chain.
On 2026-06-11, the Canadian Centre for Cyber Security issued alert AV26-588 highlighting GitLab's June 10 security advisory. It recommended that users and administrators review the advisory and update affected GitLab systems.
GitLab disclosed CVE-2026-8589, an improper input neutralization flaw affecting GitLab EE and corresponding package ranges that could let an authenticated user add unauthorized email addresses to a targeted user's account under certain conditions. The issue was fixed in versions 18.10.8, 18.11.5, and 19.0.2.
GitLab disclosed CVE-2026-10087, an Analytics Dashboard input sanitization flaw in GitLab EE that could allow a developer-level authenticated user to execute arbitrary client-side code in a targeted user's browser under certain conditions. The vulnerability affects versions before 18.10.8, 18.11.5, and 19.0.2 and was fixed in the June 2026 patch release.
On 2026-06-10, GitLab released GitLab CE/EE versions 19.0.2, 18.11.5, and 18.10.8 to fix 11 vulnerabilities and bug issues, and urged self-managed customers to upgrade immediately. GitLab said GitLab.com was already patched and that GitLab Dedicated customers did not need to take action.
On 2026-05-27, fixes were merged into the Oj Ruby JSON parser for two memory-corruption vulnerabilities later shown to be chainable into remote code execution against self-managed GitLab's notebook diff feature. The GitLab exploit research says these upstream Oj fixes preceded Oj 3.17.3 and GitLab's June 10 patched releases.
GitLab disclosed CVE-2026-6552, an improper authorization flaw in GitLab EE Group SAML identity management that could let a group Owner take over another group member's account under certain conditions. The issue affects versions before 18.10.8, 18.11.5, and 19.0.2 and was remediated in the patch release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcedepthfirst.com
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.