What is CVE-2026-16627?
A vulnerability in GitLab CE/EE allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal (CVE-2026-16627). The issue affects all versions from 19.2 before 19.2.2. Users are advised to upgrade their GitLab instances to the latest security patch.
Azərbaycanca: GitLab CE/EE məhsulunda autentifikasiya olunmuş developer roluna malik istifadəçinin CI job modalında HTML məzmununun düzgün sanitizasiya edilməməsi səbəbilə imtiyazlarını artırmasına imkan verən boşluq aşkarlanıb (CVE-2026-16627). Problem 19.2-dən 19.2.2-yə qədər olan bütün versiyalara təsir edir. İstifadəçilərə tövsiyə olunur ki, GitLab instansiyalarını ən son təhlükəsizlik yeniləməsi ilə yeniləsinlər.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GitLab
FAQ2
What level of permissions must an attacker have to exploit CVE-2026-16627?
The attacker must be an authenticated user with the developer role in GitLab.
Which GitLab versions are affected by CVE-2026-16627?
This vulnerability affects all versions from 19.2 before 19.2.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.