CVE-2026-4527: Cross-Site Request Forgery (CSRF) in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to create unauthorized Jira subscriptions for a targeted user's namespace via a specially crafted link due to missing CSRF protection.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4527?
CVE-2026-4527 has a moderate severity level due to its potential to allow unauthorized actions by unauthenticated users.
How do I fix CVE-2026-4527?
To remediate CVE-2026-4527, update GitLab CE/EE to versions 18.9.7, 18.10.6, or 18.11.3 or later.
What types of GitLab are affected by CVE-2026-4527?
CVE-2026-4527 affects both GitLab CE (Community Edition) and GitLab EE (Enterprise Edition) from versions 11.10 up to specific later versions.
What functionality does CVE-2026-4527 affect in GitLab?
CVE-2026-4527 allows an unauthenticated user to create unauthorized Jira subscriptions for targeted users.
Is there a workaround for CVE-2026-4527 before applying the fix?
Currently, there are no documented workarounds for CVE-2026-4527; upgrading to the latest version is recommended.