Junglewise Threat Intelligence

CVE-2026-8589: GitLab Enterprise Edition improper input sanitization in group settings

CVE-2026-8589 · Severity: high · CVSS 7.3 · Published 2026-06-11

Technologies: GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform used for software development and collaboration, contains a security flaw that could allow an authorized user to modify another person's account settings. Specifically, an attacker could add unauthorized email addresses to a target user's profile. This could lead to unauthorized access to sensitive project data or account takeover if the added email is used for password recovery or verification.

Technical details

A vulnerability classified as improper neutralization of input (CWE-79) exists in GitLab EE's group setting fields. Due to improper sanitization of user-supplied input, an authenticated attacker with high privileges can inject data that results in unauthorized email addresses being added to a target user's account. The attack requires network access, high privileges, and some level of user interaction under specific conditions. This could potentially lead to account takeover or unauthorized data access. The issue has been remediated in versions 18.10.8, 18.11.5, and 19.0.2.

Affected products

  • GitLab GitLab Enterprise Edition 13.1.4 to 18.10.7, 18.11 to 18.11.4, 19.0 to 19.0.1

Timeline

  • 2026-06-10: patched: GitLab released versions 18.10.8, 18.11.5, and 19.0.2 to address the issue.
  • 2026-06-11: disclosed: CVE-2026-8589 was published.

References

Related threats