Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
August 5, 2026
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds
August 5, 2026
Critical Veeam ONE Vulnerabilities Let Attackers Execute Code
August 5, 2026
Home/CyberSecurity News/GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition
CyberSecurity News

GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition

Key Takeaways GitLab has released urgent security updates for its Community and Enterprise Editions. Multiple vulnerabilities, including critical access control issues in Duo AI, denial-of-service in...

Emy Elsamnoudy
Emy Elsamnoudy
May 30, 2026 3 Min Read
64 0

Key Takeaways

  • GitLab has released urgent security updates for its Community and Enterprise Editions.
  • Multiple vulnerabilities, including critical access control issues in Duo AI, denial-of-service in the Wiki component, and authorization flaws, have been addressed.
  • Affected versions span GitLab CE/EE branches 17.1 through 19.0.
  • Self-managed instances must upgrade immediately to versions 19.0.1, 18.11.4, or 18.10.7.

GitLab has issued critical security patches for both its Community Edition (CE) and Enterprise Edition (EE) to address a range of vulnerabilities. These include significant flaws affecting Duo AI workflow runners, denial-of-service possibilities, and various authorization bypasses within recent iterations of the development platform.

Table Of Content

  • Key Takeaways
  • Critical Flaws Addressed in Duo AI and Wiki
  • Medium-Severity Authorization Issues Resolved
  • What You Should Do

On May 27, 2026, GitLab rolled out versions 19.0.1, 18.11.4, and 18.10.7. These releases are specifically designed as security updates for self-managed instances. GitLab.com has already been updated to the secure versions, and GitLab Dedicated customers are not required to take any action.

The patches rectify several security weaknesses impacting key areas such as Duo AI workflow runners, the Wiki component, GraphQL WorkItem APIs, operations, pipelines, and authentication endpoints. GitLab is strongly recommending that all administrators implement these upgrades without delay to protect their systems.

Critical Flaws Addressed in Duo AI and Wiki

Among the most critical issues resolved is a high-severity access control vulnerability, identified as CVE-2026-4868. This flaw affects GitLab EE versions from 18.8 up to, but not including, 18.10.7, 18.11.4, and 19.0.1. The vulnerability, rated 8.2 on the CVSS 3.1 scale, resides in the Duo AI workflow runners. It could allow an authenticated user, under specific circumstances, to execute certain Duo AI workflows under the identity of another user due to incorrect user identity resolution within the workflow runner logic. If unpatched, this could lead to privilege escalation or lateral movement within AI-assisted workflows.

Another significant fix targets a denial-of-service (DoS) vulnerability in the Wiki component, tracked as CVE-2026-1402. This issue impacts GitLab CE/EE from version 17.1 through unpatched 18.10, 18.11, and 19.0 branches. With a CVSS score of 6.5, the vulnerability stems from insufficient input validation, enabling an authenticated user to craft malicious content that could exhaust system resources, rendering the Wiki feature unavailable.

Additionally, CVE-2026-6713 addresses faulty authorization checks within the GraphQL WorkItem API. This could potentially allow unauthenticated users to enumerate private projects under specific conditions, carrying a CVSS score of 5.3.

Medium-Severity Authorization Issues Resolved

Several medium-severity authorization vulnerabilities have also been patched across GitLab EE operations and Duo features:

  • CVE-2026-5296 corrects an improper authorization flaw in the Duo Workflows API. This vulnerability could permit a developer-role user to bypass flow restrictions when foundational flows are enabled at the group level.
  • CVE-2026-2601 resolves missing authorization checks that could inadvertently expose sensitive deployment data to users with developer-level access.
  • CVE-2026-8716 rectifies an incorrect name resolution behavior within pipelines, which could enable access to CI data from a different reference type.
  • CVE-2026-2710 ensures that blocked Project Access Tokens are unable to access private resources through specific authentication endpoints.

All these vulnerabilities are remediated in versions 19.0.1, 18.11.4, and 18.10.7. These comprehensive updates also incorporate various stability and performance improvements, alongside updates to core components such as zlib, nginx, Mattermost, Elasticsearch indexer, and GitLab Shell.

For typical multi-node deployments, these updates do not necessitate new database migrations and can generally be implemented without downtime by following GitLab’s zero-downtime deployment guidance.

What You Should Do

  • Immediately upgrade all self-managed GitLab Community Edition (CE) and Enterprise Edition (EE) instances to versions 19.0.1, 18.11.4, or 18.10.7.
  • Monitor your GitLab instances for any unusual activity, particularly concerning Duo AI features or Wiki component usage, post-upgrade.
  • Review and align your self-managed deployment configurations with GitLab’s latest security best practices.
  • For multi-node deployments, consult GitLab’s official zero-downtime upgrade documentation to ensure a smooth transition.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CVEPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Pentest Swarm AI Tool Exposes Critical Vulnerabilities in Nmap, SQLMap, Burp, Metasploit

Next Post

Microsoft Patches Windows 11 Update KB5089573 Installation Issues

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
CISA Warns of Apache Tomcat Encryption Flaw Actively Exploited
August 5, 2026
Critical RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers
August 5, 2026
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us