CVE-2026-4922: Cross-Site Request Forgery issue in GraphQL API impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to execute GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-4922?
CVE-2026-4922 has a medium severity level due to its potential for unauthorized actions through Cross-Site Request Forgery.
How do I fix CVE-2026-4922?
To remediate CVE-2026-4922, upgrade to GitLab versions 18.9.6, 18.10.4, or 18.11.1 or later.
What types of software are affected by CVE-2026-4922?
CVE-2026-4922 affects GitLab CE and GitLab EE versions from 17.0 up to versions 18.9.6, 18.10.4, and 18.11.1.
Who is vulnerable to CVE-2026-4922?
Any user of GitLab CE or GitLab EE on the specified affected versions is vulnerable to CVE-2026-4922.
What could an attacker achieve with CVE-2026-4922?
An attacker could execute unauthorized GraphQL mutations on behalf of authenticated users due to the Cross-Site Request Forgery vulnerability.