GitLab EE CVE-2026-87719: critical 9.9 flaw leaks search credentials
GitLab Enterprise Edition has a critical insecure deserialization flaw (CWE-502, CVSS 9.9): via a GraphQL subscription, an authenticated EE user with Duo Chat access could obtain Advanced Search instance configuration and sensitive credentials. Fixes shipped on 10 September 2026 in 19.3.2, 19.2.6 and 19.1.8, and were backported to 19.0.9 and 18.11.12 on 23 September.
- CVE-2026-87719: insecure deserialization in GitLab EE, CVSS 9.9
- Entry point is a GraphQL subscription; requires EE account with Duo Chat access
- Affected: EE 18.3–18.11.11, 19.0–19.0.8, 19.1–19.1.7, 19.2–19.2.5, 19.3–19.3.1
- Rotate Advanced Search credentials as part of remediation
Read next
Security