CVE-2026-4922Patch(gitlab / gitlab)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
gitlab

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-28: 1Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-30: 104-2204-2804-30
Signal classification3 categories
Patch
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-281
General1
2026-04-301
Disclosure1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Disclosure

    GitLab CE/EE の脆弱性 CVE-2026-4922/5816/5262:ユーザーセッションが乗っ取りの可能性 https://iototsecnews.jp/2026/04/23/gitlab-fixes-flaws-that-could-allow-attackers-to-hijack-user-sessions/ 今回の脆弱性は、主にシステムの入力検証の不備や、パスの確認不足が原因で発生しています。たとえば CVE-2026-5816 や CVE-2026-5262 では、外部からの入力を正しくチェックできなかったことで、悪意のプログラム実行や情報の露出を招いてしまいました。また CVE-2026-4922 のような API の制御不備や、CVE-2026-6515 のような認証情報の管理ミスも深刻なリスクにつながります。これらは小さなミスに見えますが、攻撃者に悪用されるとシステム全体の権限を奪われる恐れがあります。ご利用のチームは、ご注意ください。 #CVE20264922 #CVE20265262 #CVE20265816 #GitLab #Vulnerability

    Post summary

    The post announces several GitLab CVEs that enable user session hijacking through input validation and API control flaws. While it discloses the technical details, it provides no proof‑of‑concept, exploit, or patch information.

    01000137
    485 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-4922 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an… https://www.cve.org/CVERecord?id=CVE-2026-4922

    Post summary

    GitLab has released a remediation for CVE‑2026‑4922 affecting versions 17.0, 18.9, 18.10, and 18.11, indicating that a patch is available.

    01000112
    57.2K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-5816 ❗ CVE-2026-5262 ❗ CVE-2026-4922 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-10/ https://t.co/qTwJBqa4lR

    Post summary

    The post lists three GitLab CVEs and links to a site for more information, without providing technical details, PoC, or exploitation context.

    00000121
    6.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---
Appgitlabgitlab18.11.0--
Appgitlabgitlab18.11.0--

Explore more