CVE-2026-2370
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.43%
- CWE
- CWE-233
- Published
- 2026-03-29
- Last modified
- 2026-07-15
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-0515 — Insufficient parameter validation in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
- CVE-2026-32998 — This vulnerability in Veeam Service Provider Console allows for remote code execution.
- CVE-2026-33585 — Arqit SKA-Platform Improper Handling of Parameters Vulnerability
- CVE-2018-25233 — WebDrive 18.00.5057 Denial of Service via Secure WebDAV
- CVE-2023-20514 — Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker...
- CVE-2025-55080 — Improper Parameter Check in ThreadX Syscall Implementation
- CVE-2025-55078 — Incomplete validation of kernel object pointers in system calls
- CVE-2025-52970 — A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and...