CVE-2026-6896Patch(gitlab / gitlab)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-07-09); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-09: 2Mentions · 2026-07-15: 1Mentions · 2026-07-23: 1Mentions · 2026-08-04: 1Patch / Workaround · 2026-07-09: 2Patch / Workaround · 2026-07-23: 1Patch / Workaround · 2026-08-04: 1Technical Details · 2026-07-09: 2Technical Details · 2026-07-23: 1Technical Details · 2026-08-04: 107-0907-1507-2308-04
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-092
Patch2
2026-07-151
Disclosure1
2026-07-231
Patch1
2026-08-041
Patch1
Full discourse5 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    The GitLab patch release fixes 8 flaws, including a high-severity cross-site scripting bug (CVE-2026-6896). Update to 19.1.2 now. #GitLab #GitLabSecurity #XSS #CrossSiteScripting #CVE #DevSecOps #PatchNow #InfoSec http://securityonline.info/gitlab-patch-release-19-1-2/

    Post summary

    GitLab has issued release 19.1.2, which includes a fix for the high‑severity XSS vulnerability CVE‑2026‑6896—users are urged to upgrade immediately.

    02031554
    12.9K followersView on X
  • Azure Kamsaki oSushi@kamsakihiyuuma
    Patch

    ①説明してなくてクソワロタ。 19.1.2系はCVSS 8.7のストアドXSS(CVE-2026-6896)を含む8件の脆弱性を修正。 Developer権限で仕込める報告もあり、self-managedは待つ理由がありません。 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/

    Post summary

    The post announces that GitLab 19.1.2 patches CVE‑2026‑6896, a stored XSS with CVSS 8.7, along with seven other flaws, and notes that self‑managed users need not wait for the fix.

    001001.2K
    734 followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CVE-2026-6896: GitLab has patched eight vulnerabilities, including a high-severity cross-site scripting (XSS) flaw. Users should update to v19.1.2. #CyberSecurity #CVE #GitLab #XSS #ThreatWire

    Post summary

    GitLab has released a patch for CVE‑2026‑6896, a high‑severity XSS flaw, and urges users to upgrade to v19.1.2 to mitigate the vulnerability.

    0001075
    66 followersView on X
  • IntegSec@integ_sec
    Patch

    CVE-2026-6896: GitLab EE Cross-Site Scripting in Vulnerability Evidence Renderer - What It Means for Your Business and How to Respond https://hubs.li/Q04rVv4S0

    Post summary

    The article announces CVE‑2026‑6896, a cross‑site scripting vulnerability in GitLab EE’s Vulnerability Evidence Renderer, and outlines remediation steps, including patching.

    0000039
    32 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-6896 ❗ CVE-2026-13320 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-15/ https://t.co/7BwwpTCpeh

    Post summary

    The message announces two GitLab CVEs (CVE-2026-6896 and CVE-2026-13320) and provides links for further information, but offers no technical details, PoC, or patch guidance.

    00000198
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---

Explore more