logo

GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition

ID: 79bc68e6-27b6-5738-a387-f3905161e61f

STIX ID: report--79bc68e6-27b6-5738-a387-f3905161e61f

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: Abinaya

...
...

GitLab released emergency security updates (19.0.1, 18.11.4, 18.10.7) for self‑managed instances to remediate multiple vulnerabilities across Duo AI workflow runners, the Wiki component, GraphQL WorkItem APIs, pipelines, and authentication endpoints — including a high‑impact access control bug (CVE‑2026‑4868, CVSS 8.2) that could let authenticated users run Duo AI workflows as other users; administrators are urged to upgrade immediately as GitLab.com is already patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.