Junglewise Threat Intelligence

CVE-2026-2370: GitLab improper authorization in Jira Connect integration

CVE-2026-2370 · Severity: high · CVSS 8.1 · Published 2026-03-30

Technologies: GitLab Enterprise Edition, GitLab Community Edition. Vendors: GitLab.

Executive brief

GitLab has fixed a security flaw in its Jira Connect integration that could allow a user with very limited permissions to steal sensitive installation credentials. By obtaining these credentials, an attacker could impersonate the GitLab application within the connected Jira environment. This could lead to unauthorized access to project data or the ability to perform actions on behalf of the official integration.

Technical details

An improper authorization check (CWE-233) exists in GitLab CE/EE within the Jira Connect installation component. An authenticated attacker with minimal workspace permissions can exploit this flaw to disclose sensitive installation credentials. These credentials can then be used to impersonate the GitLab application within the Jira environment. The vulnerability affects versions 14.3 through 18.10.0 and has been patched in versions 18.8.7, 18.9.3, and 18.10.1. The attack is network-reachable and requires low privileges but no user interaction.

Affected products

  • GitLab GitLab Community Edition 14.3 to 18.8.7, 18.9 to 18.9.3, 18.10 to 18.10.1
  • GitLab GitLab Enterprise Edition 14.3 to 18.8.7, 18.9 to 18.9.3, 18.10 to 18.10.1

Timeline

  • 2026-03-25: patched: GitLab released versions 18.10.1, 18.9.3, and 18.8.7.
  • 2026-03-30: advisory: NVD published the CVE record.

References

Related threats