GitLab Product Security Update Advisory
Overview
Several vulnerabilities have been identified in GitLab products, and security updates have been released. The affected products are GitLab CE/EE and GitLab EE; users should update to the latest patched version.
Resolved Vulnerabilities
- CVE-2026-15216: Cross-site scripting (XSS; a vulnerability that allows malicious scripts to be injected into web pages) occurring in the Analytics Dashboards pagination control in GitLab CE/EE.
- CVE-2026-15217: XSS occurring in the table field configuration of GitLab CE/EE’s Analytics Dashboards.
- CVE-2026-15423: Inadequate authorization validation vulnerability in the CI/CD Pipeline API of GitLab CE/EE.
- CVE-2026-16494: Missing authorization validation vulnerability in the ProjectsController of GitLab EE.
- CVE-2026-16627: XSS vulnerability in the CI manual task confirmation modal in GitLab CE/EE.
- CVE-2026-19228: Authorization bypass vulnerability in the Duo Workflow Service of GitLab EE.
Affected Versions and Patched Versions
- CVE-2026-15216, CVE-2026-15217, CVE-2026-15423: GitLab CE/EE 18.2 Through 18.9, 19.0 Through 19.0.6, 19.1 Through 19.1.4, And 19.2 Through 19.2.2.
- CVE-2026-15423: GitLab CE/EE 19.0 Or later but earlier than 19.0.6, 19.1 Or later but earlier than 19.1.4, 19.2 Or later but earlier than 19.2.2.
- CVE-2026-16494, CVE-2026-19228: GitLab EE 19.1 Through 19.1.4, 19.2 Through 19.2.2.
- CVE-2026-16627: GitLab CE/EE 19.2 Or later but earlier than 19.2.2.
The patched versions are 19.0.6, 19.1.4, And 19.2.2. This procedure explains how to update to the latest version that applies the Vulnerability Patch, following the instructions in GitLab Docs.