CVE-2026-9204
GitLab has fixed multiple vulnerabilities in GitLab Community Edition and Enterprise Edition (EE) versions ranging from 12.0 to 19.0.2, including major releases such as 17.x, 18.10.8, 18.11.5, and 19.0.2. The vulnerabilities affect various components of GitLab CE & EE. Authenticated users with developer permissions can execute arbitrary client-side code via the Analytics Dashboard interface due to insufficient sanitization of user input. A denial of service (DoS) can be caused on the CI/CD Catalog page by improper input sanitization, making the page unavailable. A DoS can also occur by uploading specially crafted files that lead to resource exhaustion, which can crash or make the GitLab service unresponsive. Furthermore, authenticated users can gain unauthorized access to confidential issue data due to improper authorization controls. Developer users can modify hidden merge requests due to flawed authorization, and also manipulate merge request diff views by improper handling of file names, which can hide changes during code reviews. Users with the Security Manager role can manage project security settings despite this feature being disabled, due to improper authorization. Within Group SAML identity management, group Owners can take control over other group members due to improper authorization controls. Unauthorized email addresses can be added to accounts via insufficient input sanitization in group settings. During repository import, insufficient validation of secondary URLs can lead to reading arbitrary files on the Gitaly server and access to internal network resources. Finally, an unauthenticated user can impersonate the GitLab Support Bot by injecting arbitrary content into Service Desk email responses, caused by improper handling of email templates.
CSIRTS triage
- What
- Multiple vulnerabilities allow authenticated users to execute arbitrary code, cause denial of service, and gain unauthorized access to confidential data.
- Who is affected
- Authenticated users with developer permissions in GitLab CE and EE versions 12.0 to 19.0.2 are affected.
- Urgency
- Remediation is critical due to the high impact of the vulnerabilities.
- Action
- Update to the latest version of GitLab.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-9204
Get an email if CVE-2026-9204 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
Advisory coverage (3)
- unknownNCSC-2026-0196 [1.00] [M/H] Vulnerabilities fixed in GitLab Enterprise Editionncsc-nl · 2026-06-12
- criticalGitLab Patch Release: 19.0.2, 18.11.5, 18.10.8gitlab · 2026-06-10
- criticalGitLab Patch Release: 19.0.2, 18.11.5, 18.10.8gitlab · 2026-06-10
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-9204)