CVE-2026-7250
CVE-2026-6552: A remote, authenticated threat actor without any user interaction can exploit this vulnerability in the Group SAML identity management functionality to take over another group member’s account. CVE-2026-10087: A network based, authenticated threat actor with developer-role permissions can exploit this vulnerability in the Analytics Dashboard to execute arbitrary code. The attacker can only achieve that if they manage to make the user interact with a malicious payload, which can then use the user’s browser to run client-side code. CVE-2026-7250: A remote, unauthenticated threat actor without any user interaction can exploit this vulnerability in the Grape API JSON parsing middleware to cause system disruption and eventually system crash and denial-of-service. CVE-2026-8589: A network based, authenticated threat actor with high privileges and with user interaction can exploit this vulnerability in the group setting fields to add modify user accounts without authorization using HMTL injection, for example by adding emails to another user’s account. That can allow the attacker to compromise other accounts and steal sensitive data from them.
EPSS 0.63% · 45.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GitLab | GitLab CC/EE versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, 19.0 before 19.0.2 |
Timeline
- Jun 11, 2026 CVE Published
- Jun 11, 2026 CVE Updated
- Jun 12, 2026 Coalition ESS Score
- Jun 12, 2026 Security Advisory
- Jun 16, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-multiple-high-vulnerabilities-gitlab-ccee-patch-immediately advisory
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-0-2-released/ vendor
- https://www.cve.org/CVERecord?id=CVE-2026-6552 technical
- https://www.cve.org/CVERecord?id=CVE-2026-10087 technical
- https://www.cve.org/CVERecord?id=CVE-2026-7250 technical
- https://www.cve.org/CVERecord?id=CVE-2026-8589 technical
- https://github.com/advisories/GHSA-r82j-g6q9-mvx8 technical
- https://github.com/advisories/GHSA-vcvx-j5vc-8jhr technical
- https://github.com/advisories/GHSA-cx4g-hr74-m89m technical
- https://github.com/advisories/GHSA-q9j8-24p8-jq8j technical