cognitive cybersecurity intelligence

News and Analysis

Search

GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws

GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws

GitLab has released security updates for Community Edition and Enterprise Edition, addressing 13 vulnerabilities affecting analytics dashboards, CI/CD workflows, APIs, AI services, project settings, and package management.

The company issued GitLab 19.2.2, 19.1.4, and 19.0.6 on August 12, 2026, and strongly advised self-managed customers to upgrade as soon as possible. GitLab.com is already patched, while GitLab Dedicated customers do not need to take action.

The update addresses six high-severity flaws, six medium-severity flaws, and one low-severity issue. The most serious problems include three cross-site scripting vulnerabilities and multiple authorization weaknesses that could let authenticated users perform actions beyond their intended permissions.

These bugs are especially important for organizations that use GitLab as a central platform for source code, CI/CD pipelines, package registries, and DevSecOps operations.

GitLab Patches Security Vulnerabilities

Two high-severity XSS flaws, tracked as CVE-2026-15217 and CVE-2026-15216, affect the Analytics Dashboards feature. Both bugs received a CVSS score of 8.7.

They occur because GitLab did not properly neutralize user-controlled values displayed in dashboard table cells and pagination controls.

An attacker capable of submitting crafted content could execute malicious JavaScript when another user views the affected dashboard content. Successful XSS attacks can expose session data, alter browser actions, or perform operations in the context of a targeted user.

Another high-severity issue, CVE-2026-15423, affects the CI/CD pipeline API and has a CVSS score of 8.5. GitLab said a developer-level user could, under certain conditions, run a pipeline on a protected branch without having the required push permission.

The weakness exists in pipeline reference validation. Protected branches commonly enforce stricter controls because they are used for production code, releases, or security-sensitive workflows. Unauthorized pipeline execution may pose risks to build artifacts, deployment logic, CI variables, or software supply chain processes.

GitLab also patched CVE-2026-16627, an XSS flaw in the CI manual job confirmation modal. The bug affects GitLab 19.2 versions before 19.2.2. It could allow a developer-level user to escalate privileges by exploiting improperly sanitized HTML rendered in the job modal.

The issue carries a CVSS score of 7.7. It demonstrates how UI-level injection flaws can have broader impact when they target privileged users reviewing CI/CD jobs.

Enterprise Edition users should also note authorization flaws in the Duo Workflow Service and ProjectsController. CVE-2026-19228 could allow authenticated users to attribute AI usage to another namespace.

At the same time, CVE-2026-16494 could allow changes to project settings that are normally restricted to higher-privileged roles. GitLab also resolved medium-severity authorization problems involving merge requests, external status checks, GitLab Duo settings, and AI Tool Rules.

Other patched issues include an unauthenticated denial-of-service condition in the GraphQL API JSON parser and an authorization weakness in the npm dist-tags endpoint.

The latter could allow developers to modify some package registry metadata without maintainer-level permission. Although these issues are rated lower, they can still affect service availability, project privacy, and software package integrity.

Administrators running vulnerable releases should upgrade to GitLab 19.2.2, 19.1.4, or 19.0.6, depending on their supported version branch.

Single-node deployments should plan for downtime, as the update includes database migrations that must complete before GitLab starts. Multi-node environments may apply the update without downtime when using GitLab’s zero-downtime upgrade procedures.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts