GitLab released security updates for its self-managed Community Edition and Enterprise Edition platforms, fixing 13 vulnerabilities that could let attackers run code in users’ browsers or expose sensitive project data. The most serious issues are CVE-2026-10086, an authenticated cross-site scripting flaw in the GitLab EE Analytics dashboard; CVE-2026-10712, an unauthenticated cross-site scripting flaw in the Web IDE workbench asset handler; and CVE-2026-12053, an information disclosure bug in Duo Workflows. Fixes are in GitLab CE/EE 19.1.1, 19.0.3, and 18.11.6.
Why it matters: Organizations running self-managed GitLab should update quickly, because these flaws can help attackers hijack browser sessions, tamper with settings, or expose sensitive development data and secrets. GitLab.com is already patched, but private GitLab servers remain the admins’ responsibility.
Ionut Arghire
2026.06.25
100% relevant
This article establishes a distinct patch event centered on GitLab's June 2026 CE/EE security releases and the specific CVEs fixed in those versions.
← Back to all stories