VDB

CVE-2026-7250

CVE-2026-7250 PUBLISHED CVSS 7.5 HIGH

CVE-2026-6552: A remote, authenticated threat actor without any user interaction can exploit this vulnerability in the Group SAML identity management functionality to take over another group member’s account. CVE-2026-10087: A network based, authenticated threat actor with developer-role permissions can exploit this vulnerability in the Analytics Dashboard to execute arbitrary code. The attacker can only achieve that if they manage to make the user interact with a malicious payload, which can then use the user’s browser to run client-side code. CVE-2026-7250: A remote, unauthenticated threat actor without any user interaction can exploit this vulnerability in the Grape API JSON parsing middleware to cause system disruption and eventually system crash and denial-of-service. CVE-2026-8589: A network based, authenticated threat actor with high privileges and with user interaction can exploit this vulnerability in the group setting fields to add modify user accounts without authorization using HMTL injection, for example by adding emails to another user’s account. That can allow the attacker to compromise other accounts and steal sensitive data from them.

EPSS 0.63% · 45.5th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.63%
45.5th percentile

Affected Products

VendorProductVersions
GitLabGitLab CC/EE versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, 19.0 before 19.0.2

Timeline

  • Jun 11, 2026 CVE Published
  • Jun 11, 2026 CVE Updated
  • Jun 12, 2026 Coalition ESS Score
  • Jun 12, 2026 Security Advisory
  • Jun 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›