Privilege Escalation Vulnerability in GitLab CE/EE Software by GitLab
CVE-2026-16627
7.7HIGH
What is CVE-2026-16627?
A vulnerability has been identified in GitLab CE/EE that could allow an authenticated user with developer-role permissions to escalate their privileges. This issue arises from inadequate sanitization of HTML content rendered in a Continuous Integration (CI) job modal. Users on versions from 19.2 prior to 19.2.2 are at risk and should implement the latest patches provided by GitLab to safeguard against potential exploits. Ensuring regular updates and security audits is essential for maintaining the integrity of your GitLab environment.
Affected Version(s)
GitLab 19.2 < 19.2.2
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [3nvz](https://hackerone.com/3nvz) for reporting this vulnerability through our HackerOne bug bounty program