Skip to content
Critical Vulnerabilities Discovered in GitLab Products

Critical Vulnerabilities Discovered in GitLab Products

First seen 16 Jun 2026, 03:20 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 17, 2026 at 02:44 UTC

Multiple high-severity vulnerabilities have been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) products, affecting versions 12.10.0 to 19.0.1. The vulnerabilities, including CVE-2026-6552, CVE-2026-7250, CVE-2026-8589, and CVE-2026-10087, can lead to account takeover, denial of service, unauthorized email addition, and arbitrary code execution. Attackers can exploit these vulnerabilities through improper authorization and input validation flaws. GitLab has released patches for the affected versions, urging users to update immediately. The CVSS scores for these vulnerabilities range from 7.3 to 8.7, indicating their critical nature. Users and administrators are advised to apply the updates to mitigate risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 116d ago How this analysis works

Timeline

2026-06-11
CVE-2026-6552 published
Vulnerability allows account takeover due to improper authorization in Group SAML functionality.
nvd.nist.gov
2026-06-11
CVE-2026-10087 published
Vulnerability permits arbitrary code execution via improper input sanitization in Analytics Dashboard.
nvd.nist.gov
2026-06-11
CVE-2026-8589 published
Vulnerability allows unauthorized email addition due to improper input sanitization.
nvd.nist.gov
2026-06-11
CVE-2026-7250 published
Vulnerability enables denial of service due to improper input validation in API middleware.
nvd.nist.gov
2026-06-16
Patches released by GitLab
GitLab has released security updates for affected versions, urging users to update immediately.
Csa.Sg

More articles in this cluster (25)

Following this threat?

Track CVE-2026-10087 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed