Skip to content

Warning: Multiple high vulnerabilities in GitLab CC/EE, Patch Immediately!

Ccb.Belgium.Be • June 16, 2026

GitLab Community Edition (CE) is a free, open-source platform for end-to-end software development. GitLab Enterprise Edition (EE) is a commercial offering geared toward larger teams, offering advanced features like enterprise agile planning, CI/CD, and compliance. Both the same codebase.

On 2026-06-11, multiple vulnerabilities were published GitLab CC/EE: CVE-2026-6552, CVE-2026-10087, CVE-2026-7250, CVE-2026-8589. They affect the GitLab CC/EE versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, 19.0 before 19.0.2.

CVE-2026-6552 is an Improper Access Control vulnerability, CVE-2026-10087 is a cross-site scripting (XSS) vulnerability, CVE-2026-7250 is a Denial-of-Service vulnerability (Uncontrolled Resource Consumption), CVE-2026-8589 is a HTML injection/account email abuse vulnerability (Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)).

Threat actors who exploit CVE-2026-6552 can cause a high impact on all three aspects of the CIA triad (Confidentiality, Integrity, Availability), while exploiting CVE-2026-10087 or CVE-2026-8589 can have a high impact on the Confidentiality and Integrity of the system and no impact on its Availability.

On the contrary, exploiting CVE-2026-7250 can have a high impact on the system’s Availability but no impact on either its Confidentiality or Integrity.

As of the time of writing this advisory (2026-06-12), there is no publicly available proof-of-concept (PoC) and no evidence of active exploitation in the wild of any of those four vulnerabilities.

CVE-2026-6552: A remote, authenticated threat actor without any user interaction can exploit this vulnerability in the Group SAML identity management functionality to take over another group member’s account.

CVE-2026-10087: A network based, authenticated threat actor with developer-role permissions can exploit this vulnerability in the Analytics Dashboard to execute arbitrary code. The attacker can only achieve that if they manage to make the user interact with a malicious payload, which can then use the user’s browser to run client-side code.

CVE-2026-7250: A remote, unauthenticated threat actor without any user interaction can exploit this vulnerability in the Grape API JSON parsing middleware to cause system disruption and eventually system crash and denial-of-service.

CVE-2026-8589: A network based, authenticated threat actor with high privileges and with user interaction can exploit this vulnerability in the group setting fields to add modify user accounts without authorization using HMTL injection, for example by adding emails to another user’s account. That can allow the attacker to compromise other accounts and steal sensitive data from them.

The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority, after thorough testing.

Please update to GitLab CC/EE version 18.10.8, 18.11.5, 19.0.2 or later.

The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion.

In case of an intrusion, you can report an incident via: .

While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.

Extracted Entities