GitLab patches 13 CVEs including SAML account takeover flaw
GitLab 19.0.2, 18.11.5, and 18.10.8 patch 13 security flaws, including four High-severity CVEs like SAML account takeover (CVSS 8.7) and unauthenticated API DoS. Self-managed instances must upgrade immediately; GitLab.com is already patched.
WHY IT MATTERS: Self-managed GitLab instances are exposed to account takeover, cross-site scripting, and denial-of-service attacks unless patched. Four of the thirteen fixed vulnerabilities are rated High severity, with two scoring CVSS 8.7. The most severe, CVE-2026-6552, allows an authenticated group Owner to hijack another member's account through the Group SAML Identity API. Another, CVE-2026-7250, lets unauthenticated attackers crash the Grape API JSON parsing middleware. Because GitLab is the backbone of many engineering teams' CI/CD pipelines and source control, unpatched instances present a direct path to code injection, service outages, or unauthorized repository access.
WHAT CHANGED: Versions 19.0.2, 18.11.5, and 18.10.8 were released on June 10, 2026 for both Community Edition and Enterprise Edition. The patch set addresses thirteen security issues total. High-severity fixes include an improper access control flaw in Group SAML (CVE-2026-6552), a stored XSS in Analytics Dashboard (CVE-2026-10087), an unauthenticated DoS in API middleware (CVE-2026-7250), and an HTML injection in group settings (CVE-2026-8589). Medium and Low severity fixes cover SSRF in Gitaly imports, authorization bypass in merge request diffs, and access control gaps in Todos and Security Inventory APIs. Affected versions stretch back to 12.10 for some flaws, meaning most long-running instances are vulnerable.
WHAT TO WATCH: If you run self-managed GitLab, upgrade to the latest patch for your supported version immediately. GitLab.com is already patched and Dedicated customers require no action. Full vulnerability details will be published on GitLab's public issue tracker thirty days after release, so review your access logs for suspicious SAML activity, API abuse, or merge request diff exploitation now. Schedule these patches outside normal cadence if needed; the unauthenticated DoS vector alone is exposed to the open internet.
Read the original → docs.gitlab.com
Get five bites like this every day.
Tezvyn delivers a daily feed of 60-second tech bites with quizzes to lock in what you learn.