CVE-2026-8716: Use of Incorrectly-Resolved Name or Reference in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to access CI data from a different ref type than intended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.10.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.11.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8716?
The severity of CVE-2026-8716 is medium with a score of 4.3.
How do I fix CVE-2026-8716?
To fix CVE-2026-8716, upgrade to GitLab versions 18.10.7, 18.11.4, 19.0.1 or above.
What does CVE-2026-8716 affect?
CVE-2026-8716 affects all GitLab CE and EE versions from 12.7 up to, but not including, 18.10.7, 18.11 up to 18.11.4, and 19.0 up to 19.0.1.
What type of vulnerability is CVE-2026-8716?
CVE-2026-8716 is a vulnerability related to the use of incorrectly-resolved names or references in GitLab.
Can an unauthenticated user exploit CVE-2026-8716?
No, CVE-2026-8716 requires an authenticated user to exploit the vulnerability.