CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws

Cybersecurity News Archived Aug 13, 2026 ✓ Full text saved

GitLab has released security updates for Community Edition and Enterprise Edition, addressing 13 vulnerabilities affecting analytics dashboards, CI/CD workflows, APIs, AI services, project settings, and package management. The company issued GitLab 19.2.2, 19.1.4, and 19.0.6 on August 12, 2026, and strongly advised self-managed customers to upgrade as soon as possible. GitLab.com is already patched, while […] The post GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws By Abinaya August 13, 2026 GitLab has released security updates for Community Edition and Enterprise Edition, addressing 13 vulnerabilities affecting analytics dashboards, CI/CD workflows, APIs, AI services, project settings, and package management. The company issued GitLab 19.2.2, 19.1.4, and 19.0.6 on August 12, 2026, and strongly advised self-managed customers to upgrade as soon as possible. GitLab.com is already patched, while GitLab Dedicated customers do not need to take action. The update addresses six high-severity flaws, six medium-severity flaws, and one low-severity issue. The most serious problems include three cross-site scripting vulnerabilities and multiple authorization weaknesses that could let authenticated users perform actions beyond their intended permissions. These bugs are especially important for organizations that use GitLab as a central platform for source code, CI/CD pipelines, package registries, and DevSecOps operations. GitLab Patches Security Vulnerabilities Two high-severity XSS flaws, tracked as CVE-2026-15217 and CVE-2026-15216, affect the Analytics Dashboards feature. Both bugs received a CVSS score of 8.7. They occur because GitLab did not properly neutralize user-controlled values displayed in dashboard table cells and pagination controls. An attacker capable of submitting crafted content could execute malicious JavaScript when another user views the affected dashboard content. Successful XSS attacks can expose session data, alter browser actions, or perform operations in the context of a targeted user. Another high-severity issue, CVE-2026-15423, affects the CI/CD pipeline API and has a CVSS score of 8.5. GitLab said a developer-level user could, under certain conditions, run a pipeline on a protected branch without having the required push permission. The weakness exists in pipeline reference validation. Protected branches commonly enforce stricter controls because they are used for production code, releases, or security-sensitive workflows. Unauthorized pipeline execution may pose risks to build artifacts, deployment logic, CI variables, or software supply chain processes. GitLab also patched CVE-2026-16627, an XSS flaw in the CI manual job confirmation modal. The bug affects GitLab 19.2 versions before 19.2.2. It could allow a developer-level user to escalate privileges by exploiting improperly sanitized HTML rendered in the job modal. The issue carries a CVSS score of 7.7. It demonstrates how UI-level injection flaws can have broader impact when they target privileged users reviewing CI/CD jobs. Enterprise Edition users should also note authorization flaws in the Duo Workflow Service and ProjectsController. CVE-2026-19228 could allow authenticated users to attribute AI usage to another namespace. At the same time, CVE-2026-16494 could allow changes to project settings that are normally restricted to higher-privileged roles. GitLab also resolved medium-severity authorization problems involving merge requests, external status checks, GitLab Duo settings, and AI Tool Rules. Other patched issues include an unauthenticated denial-of-service condition in the GraphQL API JSON parser and an authorization weakness in the npm dist-tags endpoint. The latter could allow developers to modify some package registry metadata without maintainer-level permission. Although these issues are rated lower, they can still affect service availability, project privacy, and software package integrity. Administrators running vulnerable releases should upgrade to GitLab 19.2.2, 19.1.4, or 19.0.6, depending on their supported version branch. Single-node deployments should plan for downtime, as the update includes database migrations that must complete before GitLab starts. Multi-node environments may apply the update without downtime when using GitLab’s zero-downtime upgrade procedures.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now. Tags cyber security cyber security news Copy URL Linkedin Twitter ReddIt Telegram Abinayahttps://cybersecuritynews.com/ Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security News Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks Cyber Security Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers Cyber Security News North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees Cyber Security News CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks Cyber Security News Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗