Junglewise Threat Intelligence

CVE-2026-6896: GitLab Enterprise Edition XSS in vulnerability evidence table renderer

CVE-2026-6896 · Severity: high · CVSS 8.7 · Published 2026-07-08

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform for software development and collaboration, contains a security flaw in how it displays vulnerability data. An attacker with developer-level access could use this flaw to run malicious scripts in the browsers of other users, such as administrators. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of the victim.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GitLab Enterprise Edition (EE) within the vulnerability evidence table renderer. The issue stems from improper sanitization of user-supplied input when generating the evidence table. An authenticated attacker with at least 'developer' role permissions can inject malicious scripts that execute in the context of another user's browser session when they view the affected page. This vulnerability is tracked as CVE-2026-6896 and carries a CVSS score of 8.7 due to the potential for session hijacking and the scope change (S:C). GitLab has released patches in versions 18.11.7, 19.0.4, and 19.1.2 to address this issue.

Affected products

  • GitLab GitLab Enterprise Edition 13.11 to 18.11.7, 19.0 to 19.0.4, 19.1 to 19.1.2

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched

References

Related threats