Urgent.News

What's breaking now, across thousands of outlets.

Tech

What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials

What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials Overview Advanced Search pushes indexed data to a backing search cluster, and CVE-2026-87719 is a critical path to its configuration. The vulnerability is CWE-502, insecure deserialization, in GitLab Enterprise Edition, and it carries a CVSS 3.1 base score of 9.9. GitLab fixed it on 10 September 2026 in…

GitLab Enterprise Edition (EE) has been hit by a critical vulnerability, CVE-2026-87719, which allows attackers with the proper access to obtain Advanced Search instance configurations and sensitive credentials. This issue, classified as CWE-502, stems from insecure deserialization when GitLab EE builds a server-side object from a client-supplied argument in a GraphQL subscription.

The vulnerability can be exploited without user interaction, making it particularly dangerous. GitLab released patches for EE versions 18.11.12, 19.0.9, 19.1.8, 19.2.6, and 19.3.2, which address the flaw. The risk is widespread, with ZoomEye estimating 1,326,958 instances of the affected software. Administrators are advised to upgrade to the latest versions, rotate credentials, and review access controls.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Starting My Developer Journey

Hey everyone! 👋 I’m a third-year AI & Data Science student, and this is my first post on DEV. I’ve spent a lot of time learning programming, DSA, web development, data analysis, and AI/ML.

More from Thursday 1 October →