CVE-2026-9694
Description
An unauthenticated attacker can impersonate the GitLab Support Bot and inject arbitrary content via a crafted Service Desk email reply due to improper template neutralization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated attacker can impersonate the GitLab Support Bot and inject arbitrary content via a crafted Service Desk email reply due to improper template neutralization.
Vulnerability
GitLab CE/EE versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 contain an improper neutralization flaw in email template processing for Service Desk replies. Under certain conditions, an unauthenticated attacker can craft an email reply that, when processed by the Service Desk, injects arbitrary content and impersonates the GitLab Support Bot [1]. The vulnerability exists in the way email templates handle specially crafted reply content.
Exploitation
An attacker only needs network access to send an email to the target GitLab instance's Service Desk email address. No authentication is required. By crafting a malicious email reply with specially formatted headers or body content, the attacker can trigger the injection during template processing. The exact injection vectors are not publicly detailed but rely on the improper neutralization of user-supplied input within the email template pipeline.
Impact
Successful exploitation allows an unauthenticated attacker to impersonate the GitLab Support Bot in Service Desk communications. The attacker can inject arbitrary content into these communications, potentially misleading users or facilitating social engineering attacks. The impact is limited to content injection within the Service Desk context; there is no disclosed ability to execute code, modify system data, or escalate privileges. The CVSS score of 2.6 (Low) reflects this constrained risk.
Mitigation
GitLab has released fixed versions 18.10.8, 18.11.5, and 19.0.2 on 2026-06-10 [1]. All users running affected versions should upgrade immediately. No workarounds have been published. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
AI Insight generated on Jun 11, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: >=15.9, <18.10.8 || >=18.11, <18.11.5 || >=19.0, <19.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
1- GitLab Patch Release: 19.0.2, 18.11.5, 18.10.8GitLab Security Releases · Jun 10, 2026