Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryidentity-authentication-vulnerabilityinternet-facing-service-vulnerabilitypatch-regression

GitLab patches 11 flaws including account takeover and XSS in CE and EE

Updated 12d agoFirst seen Jun 11, 20265 sources

GitLab released 19.0.2, 18.11.5, and 18.10.8 for self-managed Community Edition and Enterprise Edition deployments to fix 11 security vulnerabilities and additional bugs, and urged administrators to upgrade immediately. The advisory says all versions before those releases are affected, while GitLab.com has already been patched and GitLab Dedicated customers do not need to take action. GitLab also warned that the update includes database migrations that may cause downtime on single-node instances, though multi-node environments can use zero-downtime upgrade procedures.

The most severe issue, CVE-2026-6552 (CVSS 8.7), is an improper authorization flaw in GitLab EE's Group SAML identity management that could let an authenticated group Owner take over another group member's account under certain conditions. GitLab also fixed CVE-2026-10087, an Analytics Dashboard cross-site scripting flaw in GitLab EE that could allow an authenticated developer to execute arbitrary client-side code in a victim's browser. The broader patch set addresses additional risks including denial of service in Grape API JSON parsing, SSRF, unauthorized access to confidential data, and other authorization bypasses, and government and vendor advisories have called on organizations to apply the patched versions.

Share:
GitLab patches 11 flaws including account takeover and XSS in CE and EE
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 11, 202613d ago

Canadian Centre for Cyber Security highlights GitLab advisory

On 2026-06-11, the Canadian Centre for Cyber Security issued alert AV26-588 highlighting GitLab's June 10 security advisory. It recommended that users and administrators review the advisory and update affected GitLab systems.

GitLab security advisory (AV26-588) - Canadian Centre for Cyber Security

GitLab discloses CVE-2026-8589 group settings XSS flaw

GitLab disclosed CVE-2026-8589, an improper input neutralization flaw affecting GitLab EE and corresponding package ranges that could let an authenticated user add unauthorized email addresses to a targeted user's account under certain conditions. The issue was fixed in versions 18.10.8, 18.11.5, and 19.0.2.

CVE-2026-8589 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Jun 10, 202614d ago

GitLab discloses CVE-2026-10087 Analytics Dashboard XSS flaw

GitLab disclosed CVE-2026-10087, an Analytics Dashboard input sanitization flaw in GitLab EE that could allow a developer-level authenticated user to execute arbitrary client-side code in a targeted user's browser under certain conditions. The vulnerability affects versions before 18.10.8, 18.11.5, and 19.0.2 and was fixed in the June 2026 patch release.

GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8 | GitLab Docs

GitLab releases 19.0.2, 18.11.5, and 18.10.8 security patches

On 2026-06-10, GitLab released GitLab CE/EE versions 19.0.2, 18.11.5, and 18.10.8 to fix 11 vulnerabilities and bug issues, and urged self-managed customers to upgrade immediately. GitLab said GitLab.com was already patched and that GitLab Dedicated customers did not need to take action.

GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8 | GitLab Docs
Oct 1, 20188y ago

GitLab discloses CVE-2026-6552 account takeover vulnerability

GitLab disclosed CVE-2026-6552, an improper authorization flaw in GitLab EE Group SAML identity management that could let a group Owner take over another group member's account under certain conditions. The issue affects versions before 18.10.8, 18.11.5, and 19.0.2 and was remediated in the patch release.

GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8 | GitLab Docs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

GitLab patches 11 flaws including account takeover and XSS in CE and EE | Mallory