Skip to content
GitLabCVE-2026-16627

GitLab: privilege escalation

High7.7CVE-2026-16627 · Published Aug 12, 2026 · updated Aug 19, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.

GitLab advisory

Affected versions

PackageAffectedFixed in
GitLab
Product
>= 19.2, < 19.2.219.2.2
Details and references

More GitLab advisories

All GitLab
Advisory
GitLab: missing authorization
Medium4.3Aug 12
GitLab: missing authorization
Medium4.3Aug 12
GitLab: improper authorization
High8.5Aug 12
GitLab: improper authorization
Medium4.3Aug 12
GitLab: missing authorization
High7.1Aug 12
GitLab: cross-site scripting
High8.7Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.