CVE-2026-8589: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to add unauthorized email addresses to a targeted user's account due to improper sanitization of user-supplied input in certain group setting fields.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.10.8 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 18.11.5 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 19.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8589?
The severity of CVE-2026-8589 is rated as high with a score of 8.7.
How do I fix CVE-2026-8589?
To fix CVE-2026-8589, upgrade to GitLab versions 18.10.8, 18.11.5, or 19.0.2 and above.
What type of vulnerability is CVE-2026-8589?
CVE-2026-8589 is classified as a Cross-site Scripting (XSS) vulnerability.
What impact does CVE-2026-8589 have?
CVE-2026-8589 may allow an authenticated user to add unauthorized email addresses to a targeted user's account.
Which versions of GitLab are affected by CVE-2026-8589?
CVE-2026-8589 affects GitLab EE versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2.