Database/Control plane, storage & DevOps
GitLab CE/EE: stored XSS in analytics dashboard table cell rendering
Impact
The same analytics dashboard component fails to neutralise user-controlled values rendered into table cells, giving a second stored cross-site scripting path. A low-privileged user can plant a value that executes in the session of whoever opens the dashboard, and that session carries the victim's rights over CI variables, tokens and project configuration on a self-managed GitLab that feeds the GPU fleet's pipelines. It is fixed in the same releases as CVE-2026-15216, so it is one upgrade, not two. GitLab again qualifies exploitation as possible 'under certain conditions' without describing them.
Who can reach it
An authenticated GitLab user who can supply the rendered value, and a second user who views the affected dashboard. Requires user interaction.
What to do
Upgrade self-managed GitLab to 19.2.2, 19.1.4 or 19.0.6 for your branch - all versions from 18.2 are affected. Package upgrade plus GitLab service restart; the same patch release also fixes CVE-2026-15216.
References
Related entries
- Sigstore Fulcio: OIDC discovery follows cross-host redirects and leaks ServiceAccount tokensCVE-2026-49478 · Sigstore Fulcio (OIDC discovery HTTP client, cross-host redirects)High
- Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64): An out-of-boundsCVE-2026-55732 · Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64)High
- Netty: OpenSSL client path silently skips TLS hostname verification on Java 25+CVE-2026-62243 · Netty io.netty:netty-handler (SslProvider.OPENSSL client-side hostname verification)High
- Pure Storage FlashArray Purity (data path information exposure): Insufficient filtering on certain data paths exposesCVE-2026-6445 · Pure Storage FlashArray Purity (data path information exposure)High
- SeaweedFS S3 API: raw OIDC JWT bypasses IAM role trust policy and grants that role's bucket accessCVE-2026-77298 · SeaweedFS S3 API (direct OIDC bearer token to IAM role mapping)High
- OpenNebula: one.vm.exec skips the permission check, letting any user run commands in other tenants' VMsCVE-2026-84165 · OpenNebula (one.vm.exec API authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.