CRITICAL
Origin Validation Error in GitLab
Published Feb 11, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.19%
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.
Affected products
-
Affected
- ≥ 18.2, < 18.6.6
- ≥ 18.7, < 18.7.4
- ≥ 18.8, < 18.8.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 18.6.6, 18.7.4, 18.8.4 or above.
Weaknesses (1)
References (4)
- https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/ Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207019 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/555440 issue-trackingpermissions-requiredBroken LinkIssue Tracking
- https://hackerone.com/reports/3234976 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/ | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-207019 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/555440 | issue-trackingpermissions-requiredBroken LinkIssue Tracking | |
| https://hackerone.com/reports/3234976 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Feb 11, 2026
Updated Feb 26, 2026
Reserved Jul 14, 2025
Link CVE-2025-7659
CISA Vulnrichment
Updated Feb 12, 2026
Red Hat
No data
GitHub
No data