CVE-2026-5262Patch(gitlab / gitlab)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-22); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
gitlab

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-28: 1Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-30: 104-2204-2804-30
Signal classification3 categories
Patch
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-281
General1
2026-04-301
Disclosure1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Disclosure

    GitLab CE/EE の脆弱性 CVE-2026-4922/5816/5262:ユーザーセッションが乗っ取りの可能性 https://iototsecnews.jp/2026/04/23/gitlab-fixes-flaws-that-could-allow-attackers-to-hijack-user-sessions/ 今回の脆弱性は、主にシステムの入力検証の不備や、パスの確認不足が原因で発生しています。たとえば CVE-2026-5816 や CVE-2026-5262 では、外部からの入力を正しくチェックできなかったことで、悪意のプログラム実行や情報の露出を招いてしまいました。また CVE-2026-4922 のような API の制御不備や、CVE-2026-6515 のような認証情報の管理ミスも深刻なリスクにつながります。これらは小さなミスに見えますが、攻撃者に悪用されるとシステム全体の権限を奪われる恐れがあります。ご利用のチームは、ご注意ください。 #CVE20264922 #CVE20265262 #CVE20265816 #GitLab #Vulnerability

    Post summary

    The article announces several GitLab CVEs that could allow attackers to hijack user sessions through input validation and authentication flaws, but it does not provide exploit code, active attack reports, or patch details.

    01000137
    485 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-5816 ❗ CVE-2026-5262 ❗ CVE-2026-4922 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-10/ https://t.co/qTwJBqa4lR

    Post summary

    The post simply lists three GitLab CVEs and points to external links for more information.

    00000121
    6.7K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-5262 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain condi… https://www.cve.org/CVERecord?id=CVE-2026-5262

    Post summary

    GitLab has addressed CVE‑2026‑5262 with a remediation that applies to several major versions, but the provided text contains no proof‑of‑concept, exploit details, or evidence of active exploitation.

    00000147
    57.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---
Appgitlabgitlab18.11.0--
Appgitlabgitlab18.11.0--

Explore more