Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
Published: 2026-09-12
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure through credential leakage
Action: Patch immediately
AI Analysis

Impact

GitLab had a deserialization flaw (CWE-502) that could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials by crafting a specially crafted GraphQL subscription argument to bypass serialization and perform a server-side object lookup. This enables the attacker to retrieve confidential configuration information directly.

Affected Systems

GitLab Enterprise Edition is impacted. Versions 18.3 through 18.11.11, 19.0 through 19.0.8, 19.1 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1 contain the flaw. The recommended mitigation is to upgrade to GitLab EE 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2, or any newer release.

Risk and Exploitability

The CVSS score of 9.9 marks this as an extremely high risk vulnerability. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, and though it is not listed in CISA's KEV catalog, its exploitability requires only an authenticated user with Duo Chat privileges. Attackers would need to send a specially crafted GraphQL subscription request to trigger the bypass, indicating an authenticated, internal attack vector.

Generated by OpenCVE AI on September 23, 2026 at 23:07 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Apply the security update by upgrading GitLab Enterprise Edition to versions 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2, or any later release.
  • Limit Duo Chat access to trusted personnel or disable it entirely if the feature is not needed.
  • Review and tighten GraphQL subscription handling to ensure that only authorized data requests can be processed, and monitor for abnormal GraphQL activity.

Generated by OpenCVE AI on September 23, 2026 at 23:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Wed, 23 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup. GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
Title Deserialization of Untrusted Data in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-502
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-23T21:05:05.577Z

Reserved: 2026-09-09T00:34:03.671Z

Link: CVE-2026-87719

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:10.888Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-12T03:16:31.477

Modified: 2026-09-28T19:08:29.813

Link: CVE-2026-87719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T23:15:10Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data