GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 / 18.10.7) — CVE-2026-4868 GitLab Duo AI Workflow Runner Identity Confusion (CVSS 8.2) Plus DoS and Broken-Authorization Flaws

GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 / (TL-2026-0634), also tracked as GitLab May 2026 Patch Release, is a high-severity software vulnerability scored CVSS 8.2, first published 2026-05-30. It has no confirmed attribution, affects GitLab GitLab Enterprise Edition (EE), references 7 CVEs (CVE-2026-4868, CVE-2026-1402, CVE-2026-6713), maps to 12 MITRE ATT&CK techniques (T1068, T1078, T1087), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-0634

Threat ID
TL-2026-0634
Also known as
GitLab May 2026 Patch Release, GitLab 19.0.1/18.11.4/18.10.7 Security Release
Severity
HIGH
CVSS
8.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-05-30
Last reviewed
2026-05-30
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, software-development, financial, government, telecommunications, defense
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
12

On 2026-05-27 GitLab shipped emergency security releases 19.0.1, 18.11.4 and 18.10.7 for self-managed Community and Enterprise Edition, fixing seven vulnerabilities spanning Duo AI, denial-of-service and broken-authorization classes. The most severe, CVE-2026-4868 (CVSS 8.2), is an access-control flaw in Duo AI workflow runners where improper user-identity resolution lets an authenticated user trigger Duo AI workflows that execute under another user's identity, enabling lateral movement and privilege abuse. GitLab.com and Dedicated are already patched; self-managed administrators must upgrade without delay.

How GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 / works

GitLab's 2026-05-27 patch release (versions 19.0.1, 18.11.4 and 18.10.7) addresses seven security issues in self-managed GitLab Community Edition (CE) and Enterprise Edition (EE). The release is notable for clustering several flaws in GitLab's AI feature set (GitLab Duo / Duo Agent Platform) alongside classic broken-authorization and denial-of-service bugs, underscoring that AI-agent functionality is now a first-class attack surface on the DevOps platform. No public proof-of-concept and no in-the-wild exploitation were reported at disclosure; all issues were fixed prior to public detail, and GitLab.com plus GitLab Dedicated were patched ahead of the self-managed release.

The highest-severity issue, CVE-2026-4868 (CVSS 8.2, HIGH), is an improper-access-control / identity-resolution defect in the Duo AI workflow runners. When a Duo AI workflow is triggered, the runner resolves the acting user identity incorrectly under certain conditions, allowing an authenticated user to cause a workflow to execute in the security context of a different user. Because Duo workflows can read repository content, interact with project APIs and act on issues/merge requests, an attacker who can influence identity resolution can perform actions and access data as the impersonated victim — a lateral-movement and privilege-abuse primitive within a single GitLab instance. The flaw affects EE from 18.8 up to the fixed 18.10.7 / 18.11.4 / 19.0.1 builds.

The remaining six issues are lower severity but materially expand the instance's exposure. CVE-2026-1402 (CVSS ~6.5) is an authenticated denial-of-service in the Wiki: insufficient input validation lets crafted Wiki content drive uncontrolled resource consumption and render the Wiki (and potentially the worker handling it) unavailable; it reaches back to CE/EE 17.1. CVE-2026-6713 (CVSS ~5.3) is an incorrect-authorization flaw in the GraphQL WorkItem API that, under certain conditions, allows enumeration of private projects by an unauthenticated requester. CVE-2026-5296 is an improper-authorization flaw in the Duo Workflows API where a Developer-role user can bypass flow restrictions when foundational flows are enabled at the group level. CVE-2026-2601 is a missing-authorization issue in EE operations that exposes sensitive deployment data to developer-level users. CVE-2026-8716 is an incorrect ref-type name-resolution issue in pipelines that grants access to CI data belonging to a different ref type. CVE-2026-2710 hardens authentication so that blocked Project Access Tokens can no longer access private resources.

Exploit-chain perspective: most of these flaws require only a low-privileged authenticated account (Developer role or a valid user/PAT), with CVE-2026-6713 reachable pre-auth for limited private-project enumeration. A realistic chain begins with reconnaissance via the GraphQL WorkItem API (CVE-2026-6713) to enumerate otherwise-hidden private projects, followed by authenticated abuse: leveraging Duo AI identity confusion (CVE-2026-4868) to act as a higher-value user, reading deployment secrets exposed to developers (CVE-2026-2601), pivoting across ref types to reach foreign CI data (CVE-2026-8716), and abusing Duo Workflows API authorization gaps (CVE-2026-5296). The Wiki DoS (CVE-2026-1402) provides a disruptive/impact option. None of these require malware, custom tooling, or external C2 infrastructure — they are application-logic and authorization defects exploitable through GitLab's own web UI and APIs.

There is no vendor workaround other than upgrading. Defenders running self-managed GitLab should treat this as a priority patch given the wide deployment of GitLab in software-development, financial, government and technology environments and the value of source code, CI/CD pipelines and deployment credentials held within. Detection focuses on authorization-decision and identity-mismatch telemetry: Duo workflow runs whose acting identity differs from the triggering user, developer-role access to deployment/operations data, blocked-PAT access attempts, anomalous GraphQL WorkItem queries returning private nodes, and Wiki resource-exhaustion patterns.

MITRE ATT&CK techniques used in TL-2026-0634

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1087 Account Discovery; T1526 Cloud Service Discovery

Defense Evasion

T1134 Access Token Manipulation

Lateral Movement

T1210 Exploitation of Remote Services

Collection

T1213 Data from Information Repositories

Impact

T1499 Endpoint Denial of Service

Credential Access

T1528 Steal Application Access Token

lateral-movement

T1550 Use Alternate Authentication Material

Execution

T1648 Serverless Execution

Affected products and versions in GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 /

  • GitLab — GitLab Enterprise Edition (EE)
    Vulnerable versions: 18.8 up to <18.10.7; 18.11 up to <18.11.4; 19.0 up to <19.0.1
    Fixed in: 18.10.7; 18.11.4; 19.0.1
  • GitLab — GitLab Community Edition (CE)
    Vulnerable versions: 17.1 up to <18.10.7; 18.11 up to <18.11.4; 19.0 up to <19.0.1
    Fixed in: 18.10.7; 18.11.4; 19.0.1

Remediation for GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 /

Patches

  • GitLab CE/EE 19.0.1
  • GitLab CE/EE 18.11.4
  • GitLab CE/EE 18.10.7

Immediate actions

  • Upgrade self-managed GitLab CE/EE to 19.0.1, 18.11.4, or 18.10.7 without delay
  • Audit GitLab Duo AI workflow run/audit logs for identity mismatches between triggering user and acting user (CVE-2026-4868)
  • Review Project Access Token usage and confirm blocked PATs can no longer access private resources (CVE-2026-2710)
  • Review developer-role access to deployment/operations data for prior exposure (CVE-2026-2601)

Workarounds

  • No vendor workaround published — upgrading is the required mitigation
  • Temporarily disable GitLab Duo / AI workflow features if immediate patching is not possible
  • Restrict Wiki write access to trusted users to reduce CVE-2026-1402 DoS exposure

Longer-term hardening

  • Subscribe to the GitLab security release RSS feed and enforce a patch SLA for DevOps platforms
  • Restrict GitLab Duo foundational-flow enablement at the group level to least privilege
  • Apply WAF / rate-limiting to /api/graphql and Wiki endpoints to blunt enumeration and resource-exhaustion abuse
  • Continuously monitor authorization decisions and developer-role access to sensitive deployment and CI data

CVEs associated with GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 /

CVE-2026-4868, CVE-2026-1402, CVE-2026-6713, CVE-2026-5296, CVE-2026-2601, CVE-2026-8716, CVE-2026-2710

Weaknesses (CWE) in GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 /

CWE-863, CWE-639, CWE-862, CWE-285, CWE-400, CWE-20, CWE-706, CWE-287

Timeline of GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 /

  • GitLab security release blog published urging all self-managed administrators to upgrade without delay; no workarounds offered.
  • Seven CVEs publicly disclosed in the release notes; CVE-2026-4868 (Duo AI workflow identity confusion) is the highest at CVSS 8.2 HIGH.
  • GitLab.com and GitLab Dedicated are already running the patched code; no customer action required for SaaS/Dedicated.
  • GitLab publishes self-managed patch releases 19.0.1, 18.11.4 and 18.10.7 fixing seven CVEs across Duo AI, DoS and authorization classes.
  • Threadlinqs Intelligence ingests and begins tracking the release as TL-2026-0634.
  • Cyber Security News publishes analysis highlighting the Duo AI attack surface and clustered authorization flaws.

Sources cited for GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 /

Threats related to GitLab CE/EE Security Patch Release (19.0.1 / 18.11.4 /

Detection coverage for TL-2026-0634

As of 2026-05-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0634 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats