Tuesday, September 8, 2026

GitLab Fixes Flaws That Could Allow Attackers to Hijack User Sessions

GitLab has released emergency security patches addressing 11 vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE), including three high-severity flaws that could allow attackers to execute malicious code, forge requests, and steal user session tokens.

On April 22, 2026, GitLab released versions 18.11.1, 18.10.4, and 18.9.6 for both CE and EE deployments.

GitLab.com has already been updated automatically, and GitLab Dedicated customers require no action. However, all self-managed GitLab installations are strongly urged to upgrade immediately.

High-Severity Vulnerabilities

Three critical-risk flaws demand immediate attention:

  • CVE-2026-4922 (CVSS 8.1) – A Cross-Site Request Forgery (CSRF) flaw in the GraphQL API that could allow an unauthenticated attacker to execute GraphQL mutations on behalf of authenticated users, effectively hijacking their session actions. This affects all GitLab versions from 17.0 before 18.9.6.
  • CVE-2026-5816 (CVSS 8.0) – An improper path validation bug in the Web IDE asset that allows an unauthenticated user to execute arbitrary JavaScript inside a victim’s browser session, enabling full session hijacking. Affects versions from 18.10 before 18.10.4.
  • CVE-2026-5262 (CVSS 8.0) – A Cross-Site Scripting (XSS) flaw in the Storybook development environment that could expose authentication tokens to unauthenticated users through improper input validation. Affects versions from 16.1 onward.
CVE IDTypeSeverityCVSS ScoreAffected Versions
CVE-2026-4922CSRF – GraphQL APIHigh8.117.0 → 18.9.6 / 18.10.4 / 18.11.1
CVE-2026-5816Path Equivalence – Web IDEHigh8.018.10 → 18.10.4 / 18.11.1
CVE-2026-5262XSS – StorybookHigh8.016.1 → 18.9.6 / 18.10.4 / 18.11.1
CVE-2025-0186DoS – Discussions EndpointMedium6.510.6 → 18.9.6 / 18.10.4 / 18.11.1
CVE-2026-1660DoS – Jira ImportMedium6.512.3 → 18.9.6 / 18.10.4 / 18.11.1
CVE-2025-6016DoS – Notes EndpointMedium6.59.2 → 18.9.6 / 18.10.4 / 18.11.1
CVE-2025-3922DoS – GraphQL APIMedium6.512.4 → 18.9.6 / 18.10.4 / 18.11.1
CVE-2026-6515Session Expiration – Virtual RegistryMedium5.418.2 → 18.9.6 / 18.10.4 / 18.11.1
CVE-2026-5377Access Control – Issue RendererMedium4.318.11 → 18.11.1
CVE-2026-3254UI Restriction – Mermaid SandboxLow3.518.11 → 18.11.1
CVE-2025-9957Access Control – Fork APILow2.711.2 → 18.9.6 / 18.10.4 / 18.11.1

Four medium-severity Denial-of-Service (DoS) flaws were also patched. CVE-2025-0186, CVE-2025-6016, and CVE-2025-3922 all carry a CVSS score of 6.5 and could be exploited by authenticated users to exhaust server resources through crafted requests to the discussions endpoint, notes endpoint, and GraphQL API respectively.

CVE-2026-1660 similarly allows authenticated users to trigger DoS during Jira issue imports via improper input validation.

Beyond DoS, GitLab patched a medium-severity Insufficient Session Expiration bug (CVE-2026-6515, CVSS 5.4) where invalidated or incorrectly scoped credentials could still be used to access Virtual Registries, discovered internally by GitLab team member David Fernandez.

Two additional access control flaws (CVE-2026-5377 and CVE-2025-9957) allowed authenticated users to view confidential issue titles and bypass group fork-prevention policies respectively.

GitLab strongly recommends that all self-managed administrators upgrade to one of the patched versions, 18.11.1, 18.10.4, or 18.9.6, without delay.

Most vulnerabilities were responsibly disclosed via GitLab’s HackerOne bug bounty program by researchers including ahacker1, joaxcar, and pwnie. Security advisories for each flaw will be made public on GitLab’s issue tracker 30 days after the patch release date.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Related Articles

Recent News