CVE-2026-10086: GitLab EE XSS Vulnerability – High Risk Patch Available
A vulnerability in GitLab Enterprise Edition allows an authenticated developer to inject malicious code that runs in another user's browser session. An attacker with developer permissions could craft specially designed input that bypasses GitLab's safeguards, causing victims' browsers to execute arbitrary JavaScript in their security context. This is a stored or reflected cross-site scripting (XSS) vulnerability requiring the attacker to have legitimate developer access and the victim to view the malicious content.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.7 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Weaknesses (CWE)
- CWE-79
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-25 / 2026-06-26
NVD description (verbatim)
GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of another user's session, due to improper sanitization of user-supplied input.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-10086 is a CWE-79 (Cross-site Scripting) vulnerability affecting GitLab EE versions 16.4 through 18.11.5, 19.0.0 through 19.0.2, and 19.1.0. The vulnerability stems from insufficient input sanitization in a component accessible to users with developer role permissions. An authenticated attacker can inject unsanitized user input that executes client-side code in the session context of other users. The CVSS 3.1 score of 8.7 (HIGH) reflects high confidentiality and integrity impact with network-adjacent attack surface, though availability is not affected. The attack requires user interaction (UI:R) and valid developer credentials (PR:L).
Business impact
Organizations running vulnerable GitLab EE instances face risk of session hijacking, credential theft, and data exfiltration through JavaScript execution in other users' browsers. Developers with malicious intent or compromised accounts could steal authentication tokens, modify project data, or redirect users to phishing sites. The scope is changed (S:C), meaning impact extends beyond the vulnerable component to other resources. This is particularly critical for teams using GitLab for source code and CI/CD—an attacker could inject code to steal API tokens or manipulate build pipelines.
Affected systems
GitLab Enterprise Edition versions 16.4 through 18.11.5, 19.0.0 through 19.0.2, and 19.1.0 are affected. GitLab Community Edition is not impacted. Organizations should check their GitLab instance version immediately to determine exposure. Self-managed and SaaS deployments running any of these version ranges require mitigation.
Exploitability
Exploitation requires valid GitLab credentials with developer role or higher. The attack vector is network-based (AV:N), meaning remote exploitation is possible. However, the vulnerability also depends on user interaction (UI:R)—the victim must view the injected content for the code to execute. This combination makes it moderately exploitable: attackers with existing developer access can inject payloads, but success depends on social engineering or timing to ensure targets interact with the malicious content.
Remediation
Upgrade to patched versions immediately: GitLab EE 18.11.6 or later, 19.0.3 or later, or 19.1.1 or later. Verify the specific version you are running and plan an upgrade path. For organizations unable to patch immediately, restrict developer-role permissions to trusted personnel only and monitor for suspicious input submissions or changes in sensitive areas where developers can contribute content.
Patch guidance
Apply security updates according to your upgrade cycle: standard deployments should update to the next stable release (18.11.6+, 19.0.3+, or 19.1.1+) within the next 7–14 days. Enterprise customers with SLA commitments should coordinate with GitLab support for scheduling. Test patches in a staging environment first. After upgrade, verify the vulnerability is resolved by checking your GitLab version in the admin panel. Monitor release notes for any follow-up security advisories related to sanitization improvements.
Detection guidance
Review audit logs for developer-role accounts creating or modifying content in merge requests, wikis, issues, or comments. Look for unusual HTML, script tags, or JavaScript patterns in submitted input. Enable GitLab's detailed audit logging if available. Security teams should consider Web Application Firewall (WAF) rules to detect and block common XSS payloads at the network layer. Monitor for any alerts related to cross-site scripting attempts in your environment. Conduct code review of any recent changes by developers with suspicious activity.
Why prioritize this
While not yet listed on CISA's Known Exploited Vulnerabilities catalog, this HIGH severity vulnerability merits urgent attention because it enables authenticated account abuse and cross-session code execution, putting user data and CI/CD pipelines at risk. The requirement for developer credentials limits the attack surface to internal threats or compromised developer accounts, but the wide version range affected (spanning major releases) means many organizations are likely vulnerable. Prompt patching prevents both external and insider attacks.
Risk score, explained
The CVSS 3.1 score of 8.7 reflects high severity: the attack requires network access and valid developer credentials (reducing ease), but successful exploitation grants high confidentiality and integrity impact with scope change. The requirement for user interaction prevents immediate exploitation but does not eliminate risk in environments where developers are socially engineered or malicious. The score appropriately prioritizes this as a non-critical-but-urgent issue requiring action within days, not weeks.
Frequently asked questions
Do I need to upgrade immediately if I run GitLab Community Edition?
No. This vulnerability affects GitLab Enterprise Edition only. Community Edition users are not impacted and do not require a security update.
What permissions does an attacker need to exploit this?
An attacker must have valid GitLab credentials with developer role permissions or higher. This means the threat is primarily from malicious developers, compromised developer accounts, or supply-chain attacks if developer credentials are stolen.
Can this vulnerability be exploited remotely without user interaction?
Exploitation requires the victim to view the malicious content (user interaction). However, in many GitLab workflows (reviewing merge requests, reading wiki pages, checking issues), user interaction is routine, making the practical exploitation risk higher than the CVSS score alone suggests.
If we restrict developer permissions, are we fully protected?
Restricting developer permissions reduces risk but does not fully mitigate the vulnerability. Only patching to 18.11.6, 19.0.3, or 19.1.1 (or later) eliminates the underlying flaw. Restrict permissions as a temporary compensating control while you plan your upgrade.
This analysis is based on CVE-2026-10086 official description and CVSS metrics published by GitLab security advisories. SEC.co has not independently verified exploit code or attack conditions. Organizations should verify patch availability and compatibility with their environment by consulting the official GitLab security advisory and release notes. This explainer does not constitute security advice specific to your deployment; consult with your GitLab administrator and security team before making changes. All version numbers and patch guidance should be validated against the official GitLab security portal before implementation. Source: NVD (public-domain), retrieved 2026-08-02. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10087HIGHGitLab EE Analytics Dashboard XSS Vulnerability – Patch Guide
- CVE-2026-10712HIGHGitLab XSS Vulnerability – Patch Now for 18.11, 19.0, 19.1
- CVE-2026-8589HIGHGitLab EE Email Injection Vulnerability – Account Takeover Risk
- CVE-2016-20066HIGHWordPress CP Polls 1.0.8 Persistent XSS Vulnerability
- CVE-2016-20084HIGHWordPress Appointment-Booking-Calendar Unauthenticated XSS and Privilege Escalation
- CVE-2023-33999HIGHDOM-Based XSS in WP Mail Log Plugin – Analysis & Remediation
- CVE-2023-45795HIGHXSS in Pilz PASvisu Builder Component – Patch Guidance
- CVE-2023-45796HIGHStored XSS in Pilz PASvisu & PMI Industrial Software – Remediation Guide