CVE-2026-5816:
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.
Score
A numerical rating that indicates how dangerous this vulnerability is.
8.0HighA numerical rating that indicates how dangerous this vulnerability is.
- Published Date:Apr 22, 2026
- CISA KEV Date:*No Data*
- Industries Affected:20
Exploitability
- Score:1.6
- Attack Vector:NETWORK
- Attack Complexity:HIGH
- Privileges Required:NONE
- User Interaction:REQUIRED
- Scope:CHANGED
Impact
- Score:5.8
- Confidentiality Impact:HIGH
- Integrity Impact:HIGH
- Availability Impact:NONE
Description Preview
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.
Industries Affected
Below is a list of industries most commonly impacted or potentially at risk based on intelligence.
Low