VDB

CVE-2026-8716

CVE-2026-8716 PUBLISHED CVSS 4.3 MEDIUM

Reported by GitLab · Published May 27, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
GitLabGitLab12.7, 18.11, 19.0
wolfigitlab-runner-19.00, 0, 0
chainguardgitlab-runner-fips-19.00, 0, 0
chainguardgitlab-runner-19.00, 0, 0
wolfigitlab-runner-18.110, 0, 0
GitLabGitLab12.7, 19.0, 18.11
chainguardgitlab-rails-ce-fips-19.00, 0, 0
chainguardgitlab-rails-ce-19.00, 0, 0

Timeline

  • May 27, 2026 CVE Published
  • May 27, 2026 CVE Updated
  • May 28, 2026 EPSS Score
  • May 28, 2026 Coalition ESS Score
  • May 29, 2026 EPSS Score
  • May 29, 2026 Security Advisory
  • May 30, 2026 EPSS Score
  • May 31, 2026 EPSS Score
  • Jun 1, 2026 EPSS Score
  • Jun 5, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›