VYPR
Vypr IntelligenceAI-generatedSep 24, 2026· 4 CVEs

GitLab: Two Critical RCE and Two Medium Flaws Patched in Single September Disclosure

GitLab Inc. patched four vulnerabilities, including two critical remote code execution flaws, in a single coordinated disclosure event on September 24, 2026.

Key findings

  • Two critical (CVSSv3 9.9) and two medium (CVSSv3 4.3) vulnerabilities disclosed for GitLab CE/EE.
  • Critical flaws CVE-2026-93577 and CVE-2026-89078 allow arbitrary code execution for authenticated users.
  • Medium flaws CVE-2026-92530 and CVE-2026-92529 permit merge request spoofing and AI governance bypass, respectively.
  • All vulnerabilities patched in GitLab versions 19.2.7, 19.3.3, and 19.4.1.
  • Urgent upgrade recommended for all self-managed GitLab installations.

On September 24, 2026, GitLab Inc. disclosed four vulnerabilities affecting GitLab Community Edition (CE) and Enterprise Edition (EE). The batch includes two critical severity flaws, both rated CVSSv3 9.9, and two medium severity flaws, each with a CVSSv3 score of 4.3. These vulnerabilities were patched in GitLab versions 19.2.7, 19.3.3, and 19.4.1.

Two of the critical vulnerabilities, CVE-2026-93577 and CVE-2026-89078, could allow an authenticated user to execute arbitrary code on the GitLab server. CVE-2026-93577 is due to an integer overflow issue when compiling specially crafted code, while CVE-2026-89078 stems from a double free issue when parsing a specially crafted regular expression. Both of these critical vulnerabilities affect all versions prior to the patched releases.

The two medium severity vulnerabilities include CVE-2026-92530, which could permit an authenticated user to spoof merge request authorship and attribute content to arbitrary users. Additionally, CVE-2026-92529 allows an authenticated user with developer-role permissions to bypass admin-configured AI tool governance controls for workflows in namespaces.

All four vulnerabilities affect versions prior to 19.2.7, 19.3.3, and 19.4.1. GitLab strongly recommends that all self-managed GitLab installations be upgraded to one of these patched versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not require any action.

This coordinated disclosure highlights the importance of timely patching for self-managed instances to mitigate risks associated with authenticated threats. Users should ensure their instances are updated to the latest available versions to protect against these security weaknesses.

AI-written article. Grounded in 4 CVE records listed below.