GitLab Enterprise Edition patched critical vulnerability exposing search credentials
GitLab disclosed a critical vulnerability in its Enterprise Edition on September 10, 2026. The flaw, tracked as CVE-2026-87719, involves insecure deserialization and carries a CVSS score of 9.9. An authenticated attacker could exploit it via GraphQL to access Advanced Search configuration and sensitive credentials. GitLab released patches in versions 19.3.2, 19.2.6, and 19.1.8, with backports to earlier releases. The company advises administrators to upgrade immediately and rotate exposed credentials.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in