CVE-2026-16627: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 19.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16627?
CVE-2026-16627 has a severity rating of 7.7, categorized as high.
How do I fix CVE-2026-16627?
To fix CVE-2026-16627, upgrade to GitLab CE/EE version 19.2.2 or later.
What does CVE-2026-16627 exploit?
CVE-2026-16627 exploits improper sanitization of HTML content in GitLab, allowing for cross-site scripting.
Who is affected by CVE-2026-16627?
CVE-2026-16627 affects all authenticated users with developer-role permissions in GitLab versions prior to 19.2.2.
What types of attacks can result from CVE-2026-16627?
CVE-2026-16627 can lead to privilege escalation due to cross-site scripting vulnerabilities.