chiprook
← Security
SecurityOctober 1, 2026, 22:20

GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials

GitLab Enterprise Edition has a critical insecure deserialization flaw (CWE-502, CVSS 9.9): via a GraphQL subscription, an authenticated EE user with Duo Chat access could obtain Advanced Search instance configuration and sensitive credentials. Fixes shipped on 10 September 2026 in 19.3.2, 19.2.6 and 19.1.8, and were backported to 19.0.9 and 18.11.12 on 23 September.

GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials
#GitLab
Read next
Security

GitLab patches 11 flaws, including two 9.9-rated RCEs

Security

LXD hit by three critical flaws rated up to 9.9

Security

GitLab ships critical patch across 19.4, 19.3 and 19.2

Security

CVE-2026-75682 in Adobe Connect: SQL injection rated 9.9 leads to code execution