NCSC-2026-0297 [1.00] [M/H] Vulnerabilities patched in GitLab Enterprise Edition and Community Edition
GitLab has patched multiple vulnerabilities in GitLab Enterprise Edition (EE) and Community Edition (CE) versions ranging from 12.0 through 19.2.2. The vulnerabilities concern various aspects of GitLab, including improper privilege assignment where users with a pending membership status could unintentionally inherit permissions from custom roles. Furthermore, there are missing authorization controls on API endpoints, allowing users with developer roles to access external status check configurations and limited merge request information from private projects. A Denial-of-Service is also possible through improper input validation, and cross-site scripting (XSS) vulnerabilities in the analytics dashboard component due to insufficient sanitization of user input. Additionally, users with lower privileges could modify certain package registry metadata and trigger CI/CD pipelines on protected branches without proper permissions. There were also authorization issues that made it possible to modify project and group settings without authorization, and a GraphQL query that provided access to policy configurations of disallowed namespaces. Finally, there was an issue with improper authorization of identity information, resulting in incorrect assignment of AI usage to other namespaces. These vulnerabilities can lead to unauthorized access, data modification, privilege escalation, and disruption of availability within the GitLab Enterprise Edition environment.
CSIRTS triage
- What
- Multiple vulnerabilities including improper privilege assignment for pending members, missing authorization on API endpoints, DoS via input validation, XSS in analytics, and privilege escalation in package registry.
- Who is affected
- GitLab Enterprise Edition and Community Edition instances running versions 12.0 through 19.2.2.
- Urgency
- High urgency; multiple attack vectors enable privilege escalation, unauthorized access, and service disruption.
- Action
- Update GitLab Enterprise Edition and Community Edition to versions above 19.2.2 with patches for CVE-2025-9486, CVE-2026-4879, CVE-2026-6821, CVE-2026-7427, CVE-2026-8667, CVE-2026-15216, CVE-2026-15217, and CVE-2026-15423.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch GitLab
Get an email when a new GitLab advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0297
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-94860.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-48790.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-68210.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-74270.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-86670.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-152160.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-152170.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-154230.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-164940.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-166270.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-9486 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-4879 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6821 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7427 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8667 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15216 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15217 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15423 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16494 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16627 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18244 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18433 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19228 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] GitLab: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in GitLab (August 13, 2026)cert-fr-avis
- mediumCVE-2026-6821: GitLab has remediated an issue in GitLab EE affecting all versions from 12.0 before 19.0.6, 19.…nvd
- mediumCVE-2026-4879: GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.…nvd
- highCVE-2026-19228: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and…nvd
- mediumCVE-2026-18433: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and…nvd
- highCVE-2026-16494: GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and…nvd
- highCVE-2026-15217: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6,…nvd
- highCVE-2026-15216: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6,…nvd
- lowCVE-2025-9486: GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.…nvd
- mediumCVE-2026-8667: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, …nvd
- mediumCVE-2026-7427: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, …nvd
Recent advisories for GitLab Enterprise Edition
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0222 [1.00] [M/H] Vulnerabilities fixed in GitLab Enterprise Edition and Community Editionncsc-nl · 2026-07-10
- unknownNCSC-2026-0211 [1.00] [M/H] Vulnerabilities fixed in GitLab Community Edition and Enterprise Editionncsc-nl · 2026-06-25
- unknownNCSC-2026-0196 [1.00] [M/H] Vulnerabilities fixed in GitLab Enterprise Editionncsc-nl · 2026-06-12
- criticalexploitedCVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerabilitycisa-kev · 2026-02-03
- criticalexploitedCVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerabilitycisa-kev · 2024-05-01
- criticalexploitedCVE-2021-22205: GitLab Community and Enterprise Editions Remote Code Execution Vulnerabilitycisa-kev · 2021-11-03
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13