CVE-2026-9694
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply due to improper neutralization in email template processing.
Scoring
- Severity
- LOW
- CVSS base score
- 2.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-153
- Published
- 2026-06-11
- Last modified
- 2026-06-11
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2025-53006 — Dataease PostgreSQL & Redshift Data Source JDBC Connection Parameters Bypass Vulnerability
- CVE-2025-53005 — Dataease PostgreSQL Data Source JDBC Connection Parameters Bypass Vulnerability
- CVE-2025-53004 — Dataease Redshift Data Source JDBC Connection Parameters Bypass Vulnerability
- CVE-2025-49003 — Dataease H2 JDBC Connection Remote Code Execution