PT-2026-34518 · Gitlab · Gitlab Ce/Ee

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-5262

CVSS v3.1

8.0

High

AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 16.1.0 through 18.9.5 GitLab CE/EE versions 18.10 through 18.10.3 GitLab CE/EE versions 18.11 through 18.11.0
Description Improper input validation under certain conditions could allow an unauthenticated user to access tokens in the Storybook development environment.
Recommendations Update to version 18.9.6 Update to version 18.10.4 Update to version 18.11.1

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-5262

Affected Products

Gitlab Ce/Ee