{"id":13277,"date":"2026-05-31T10:03:53","date_gmt":"2026-05-31T10:03:53","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/31\/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition\/"},"modified":"2026-05-31T10:03:53","modified_gmt":"2026-05-31T10:03:53","slug":"gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/31\/gitlab-patches-multiple-duo-ai-dos-and-authorization-flaws-in-community-and-enterprise-edition\/","title":{"rendered":"GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition"},"content":{"rendered":"<p>    GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial\u2011of\u2011service, and authorization flaws in recent versions of the platform.<\/p>\n<p class=\"wp-block-paragraph\">On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7 as<a href=\"https:\/\/cybersecuritynews.com\/gitlab-security-update-2\/\" target=\"_blank\" rel=\"noreferrer noopener\"> security patch<\/a> releases for self\u2011managed instances.<\/p>\n<p class=\"wp-block-paragraph\">These builds fix several vulnerabilities across Duo AI workflow runners, the Wiki component, GraphQL WorkItem APIs, operations, pipelines, and authentication endpoints, and GitLab is urging all administrators to upgrade without delay.<\/p>\n<p class=\"wp-block-paragraph\">GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take any action.<\/p>\n<h2 id=\"h-gitlab-fixes-duo-ai-dos-flaws\" class=\"wp-block-heading\">\n<strong>GitLab Fixes Duo AI, DoS<\/strong> <strong>Flaws<\/strong><br \/>\n<\/h2>\n<p class=\"wp-block-paragraph\">The most severe issue is a high\u2011impact access control flaw in Duo AI workflow runners, tracked as CVE\u20112026\u20114868, which affects GitLab EE from 18.8 up to but not including 18.10.7, 18.11.4, and 19.0.1.<\/p>\n<p class=\"wp-block-paragraph\">Under specific conditions, an authenticated user could trigger certain Duo AI workflows to execute under another user\u2019s identity due to improper user identity resolution in the workflow runner logic, with a CVSS 3.1 score of 8.2.<\/p>\n<p class=\"wp-block-paragraph\">This could enable lateral movement or privilege abuse within AI\u2011assisted workflows if left unpatched.<\/p>\n<p class=\"wp-block-paragraph\">GitLab also fixed a <a href=\"https:\/\/cybersecuritynews.com\/gitlab-vulnerabilities-xss-and-dos\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial\u2011of\u2011service vulnerability<\/a> in the Wiki component, tracked as CVE\u20112026\u20111402, which impacts GitLab CE\/EE from 17.1 through unpatched 18.10, 18.11, and 19.0 branches.<\/p>\n<p class=\"wp-block-paragraph\">Due to insufficient input validation, an authenticated user could craft content that exhausts resources and renders the Wiki unavailable, earning a CVSS score of 6.5.<\/p>\n<p class=\"wp-block-paragraph\">In parallel, CVE\u20112026\u20116713 addresses incorrect <a href=\"https:\/\/cybersecuritynews.com\/graphql-security-2024-report\/\" target=\"_blank\" rel=\"noreferrer noopener\">authorization checks in the GraphQL<\/a> WorkItem API that could allow unauthenticated users to enumerate private projects under certain conditions, rated 5.3 on the CVSS scale.<\/p>\n<p class=\"wp-block-paragraph\">Several medium\u2011severity authorization issues have also been resolved in GitLab EE operations and Duo features.<\/p>\n<p class=\"wp-block-paragraph\">CVE\u20112026\u20115296 fixes improper authorization in the Duo Workflows API that could let a developer\u2011role user bypass flow restrictions when foundational flows are enabled at the group level.<\/p>\n<p class=\"wp-block-paragraph\">CVE\u20112026\u20112601 corrects missing authorization checks that could <a href=\"https:\/\/cybersecuritynews.com\/gitlab-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">expose sensitive deployment<\/a> data to developer\u2011level users.<\/p>\n<p class=\"wp-block-paragraph\">Additionally, CVE\u20112026\u20118716 corrects an incorrect name resolution behavior in pipelines that could allow access to CI data from a different ref type.<\/p>\n<p class=\"wp-block-paragraph\">CVE\u20112026\u20112710 ensures that blocked Project Access Tokens cannot access private resources via certain authentication endpoints.<\/p>\n<p class=\"wp-block-paragraph\">All of these flaws are remediated in versions 19.0.1, 18.11.4, and 18.10.7, which also bundle multiple stability and performance backports, including updates to <a href=\"https:\/\/cybersecuritynews.com\/zlib-buffer-overflow-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">zlib<\/a>, <a href=\"https:\/\/cybersecuritynews.com\/nginx-poolslip-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">nginx<\/a>, Mattermost, Elasticsearch indexer, and GitLab Shell.<\/p>\n<p class=\"wp-block-paragraph\">The updates do not introduce new database migrations and, in typical multi\u2011node deployments, can be rolled out without downtime when following <a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-0-1-released\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GitLab\u2019s zero\u2011downtime guidance<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Organizations running affected versions are strongly advised to prioritize upgrades, monitor their instances for abuse of Duo AI or Wiki features, and align with GitLab\u2019s published best practices for securing self\u2011managed deployments.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><b>Uncover Shadow APIs, close OWASP gaps <\/b>\u2014 <a href=\"https:\/\/www.prophaze.com\/webinar-registration-closing-visibility-gaps-in-waap\/?utm_source=Cyber+security+news+&amp;utm_medium=Article+&amp;utm_campaign=Cyber+news#\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Join a Free Webinar<\/a> to secure every API at runtime.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gitlab-patches-duo-ai-dos-flaws\/\">GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gitlab-patches-duo-ai-dos-flaws\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GitLab Patches Multiple Duo AI, DoS, and Authorization Flaws in Community and Enterprise Edition GitLab has released emergency security updates for both Community Edition (CE) and Enterprise Edition (EE), addressing multiple Duo AI, denial\u2011of\u2011service, and authorization flaws in recent versions of the platform. On May 27, 2026, GitLab shipped versions 19.0.1, 18.11.4, and 18.10.7 as [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2294,416],"tags":[130],"class_list":["post-13277","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-gitlab","category-vulnerabilities","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13277"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13277"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13277\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13277"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13277"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}