GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition
Key Takeaways GitLab has released urgent security updates for its Community and Enterprise Editions. Multiple vulnerabilities, including critical access control issues in Duo AI, denial-of-service in...
Key Takeaways
- GitLab has released urgent security updates for its Community and Enterprise Editions.
- Multiple vulnerabilities, including critical access control issues in Duo AI, denial-of-service in the Wiki component, and authorization flaws, have been addressed.
- Affected versions span GitLab CE/EE branches 17.1 through 19.0.
- Self-managed instances must upgrade immediately to versions 19.0.1, 18.11.4, or 18.10.7.
GitLab has issued critical security patches for both its Community Edition (CE) and Enterprise Edition (EE) to address a range of vulnerabilities. These include significant flaws affecting Duo AI workflow runners, denial-of-service possibilities, and various authorization bypasses within recent iterations of the development platform.
Table Of Content
On May 27, 2026, GitLab rolled out versions 19.0.1, 18.11.4, and 18.10.7. These releases are specifically designed as security updates for self-managed instances. GitLab.com has already been updated to the secure versions, and GitLab Dedicated customers are not required to take any action.
The patches rectify several security weaknesses impacting key areas such as Duo AI workflow runners, the Wiki component, GraphQL WorkItem APIs, operations, pipelines, and authentication endpoints. GitLab is strongly recommending that all administrators implement these upgrades without delay to protect their systems.
Critical Flaws Addressed in Duo AI and Wiki
Among the most critical issues resolved is a high-severity access control vulnerability, identified as CVE-2026-4868. This flaw affects GitLab EE versions from 18.8 up to, but not including, 18.10.7, 18.11.4, and 19.0.1. The vulnerability, rated 8.2 on the CVSS 3.1 scale, resides in the Duo AI workflow runners. It could allow an authenticated user, under specific circumstances, to execute certain Duo AI workflows under the identity of another user due to incorrect user identity resolution within the workflow runner logic. If unpatched, this could lead to privilege escalation or lateral movement within AI-assisted workflows.
Another significant fix targets a denial-of-service (DoS) vulnerability in the Wiki component, tracked as CVE-2026-1402. This issue impacts GitLab CE/EE from version 17.1 through unpatched 18.10, 18.11, and 19.0 branches. With a CVSS score of 6.5, the vulnerability stems from insufficient input validation, enabling an authenticated user to craft malicious content that could exhaust system resources, rendering the Wiki feature unavailable.
Additionally, CVE-2026-6713 addresses faulty authorization checks within the GraphQL WorkItem API. This could potentially allow unauthenticated users to enumerate private projects under specific conditions, carrying a CVSS score of 5.3.
Medium-Severity Authorization Issues Resolved
Several medium-severity authorization vulnerabilities have also been patched across GitLab EE operations and Duo features:
- CVE-2026-5296 corrects an improper authorization flaw in the Duo Workflows API. This vulnerability could permit a developer-role user to bypass flow restrictions when foundational flows are enabled at the group level.
- CVE-2026-2601 resolves missing authorization checks that could inadvertently expose sensitive deployment data to users with developer-level access.
- CVE-2026-8716 rectifies an incorrect name resolution behavior within pipelines, which could enable access to CI data from a different reference type.
- CVE-2026-2710 ensures that blocked Project Access Tokens are unable to access private resources through specific authentication endpoints.
All these vulnerabilities are remediated in versions 19.0.1, 18.11.4, and 18.10.7. These comprehensive updates also incorporate various stability and performance improvements, alongside updates to core components such as zlib, nginx, Mattermost, Elasticsearch indexer, and GitLab Shell.
For typical multi-node deployments, these updates do not necessitate new database migrations and can generally be implemented without downtime by following GitLab’s zero-downtime deployment guidance.
What You Should Do
- Immediately upgrade all self-managed GitLab Community Edition (CE) and Enterprise Edition (EE) instances to versions 19.0.1, 18.11.4, or 18.10.7.
- Monitor your GitLab instances for any unusual activity, particularly concerning Duo AI features or Wiki component usage, post-upgrade.
- Review and align your self-managed deployment configurations with GitLab’s latest security best practices.
- For multi-node deployments, consult GitLab’s official zero-downtime upgrade documentation to ensure a smooth transition.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.