logo

CVE-2026-10087: GitLab EE Stored XSS via Developer Role

ID: f0b66e3c-56da-590b-8638-f66ec3feab9a

STIX ID: report--f0b66e3c-56da-590b-8638-f66ec3feab9a

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

...
...

## Executive Summary CVE-2026-10087 is a stored XSS in GitLab Enterprise Edition (CVSS 8.7) that enables authenticated Developer-role users to inject JavaScript executed in other users' sessions — potentially allowing session theft, API misuse, privilege escalation, and CI/CD supply-chain compromise; affected self-managed EE versions are 17.1–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1 and are fixed in 18.10.8, 18.11.5, and 19.0.2, with urgent upgrades and access restrictions recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.