CVE-2026-6515Patch(gitlab / gitlab)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gitlab

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-30: 104-2204-30
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-301
Disclosure1
Full discourse2 posts
  • iototsecnews@iototsecnews
    Disclosure

    GitLab CE/EE の脆弱性 CVE-2026-4922/5816/5262:ユーザーセッションが乗っ取りの可能性 https://iototsecnews.jp/2026/04/23/gitlab-fixes-flaws-that-could-allow-attackers-to-hijack-user-sessions/ 今回の脆弱性は、主にシステムの入力検証の不備や、パスの確認不足が原因で発生しています。たとえば CVE-2026-5816 や CVE-2026-5262 では、外部からの入力を正しくチェックできなかったことで、悪意のプログラム実行や情報の露出を招いてしまいました。また CVE-2026-4922 のような API の制御不備や、CVE-2026-6515 のような認証情報の管理ミスも深刻なリスクにつながります。これらは小さなミスに見えますが、攻撃者に悪用されるとシステム全体の権限を奪われる恐れがあります。ご利用のチームは、ご注意ください。 #CVE20264922 #CVE20265262 #CVE20265816 #GitLab #Vulnerability

    Post summary

    The post reports on GitLab CE/EE vulnerabilities (CVE‑2026‑4922, 5816, 5262) that could lead to session hijacking, providing technical details of the flaws but offering no PoC, exploit code, or patch information.

    01000137
    485 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-6515 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a … https://www.cve.org/CVERecord?id=CVE-2026-6515

    Post summary

    The notice announces that GitLab has issued a remediation for CVE-2026-6515 across multiple versions, focusing on the patch update and affected releases.

    00000164
    57.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---
Appgitlabgitlab18.11.0--
Appgitlabgitlab18.11.0--

Explore more