Arbitrary Command Execution in GitLab EE Affects Multiple Versions
CVE-2026-18252

7.3HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-18252?

CVE-2026-18252 is a critical vulnerability identified in GitLab Enterprise Edition (EE), affecting various versions from 18.9 to before 19.1.7, 19.2 to before 19.2.5, and 19.3 to before 19.3.1. GitLab is a widely-used platform for version control and collaborative software development, facilitating code management, project planning, and CI/CD (Continuous Integration/Continuous Deployment) processes. This vulnerability arises from a flaw in the Claude agent's configuration processing, allowing an authenticated user with developer-role permissions to potentially execute arbitrary commands in a CI context. Such an intrusion could lead to unauthorized manipulation of critical systems, data leakage, and severe disruptions to a company's software development lifecycle.

Potential impact of CVE-2026-18252

  1. Arbitrary Command Execution: The most significant impact of this vulnerability is the ability for a developer-level user to execute arbitrary commands. This could lead to complete system compromise, allowing attackers to manipulate data, deploy malicious code, or disrupt services.

  2. Data Breaches: Exploitation of this vulnerability could result in unauthorized access to sensitive information stored within GitLab repositories, including proprietary code, personal data, and project details. This exposure can lead to compliance violations and loss of customer trust.

  3. Disruption of CI/CD Processes: By executing arbitrary commands within the CI environment, malicious actors could disrupt the continuous integration and deployment flows, leading to delayed software releases and increased operational costs while organizations scramble to remediate the issues introduced through the exploitation.

Affected Version(s)

GitLab 18.9 < 19.1.7

GitLab 19.2 < 19.2.5

GitLab 19.3 < 19.3.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [thwin_htet](https://hackerone.com/thwin_htet) for reporting this vulnerability through our HackerOne bug bounty program
.