CVE-2026-9694
Undergoing Analysis
Undergoing Analysis - In Progress
GitLab Support Bot Impersonation via Email Template Injection
Publication date: 2026-06-11
Last updated on: 2026-06-11
Assigner: GitLab Inc.
Description
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unauthenticated user to impersonate the GitLab Support Bot and inject arbitrary content via a specially crafted Service Desk email reply due to improper neutralization in email template processing.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gitlab | gitlab_ce | From 15.9 (inc) to 18.10.8 (exc) |
| gitlab | gitlab_ee | From 15.9 (inc) to 18.10.8 (exc) |
| gitlab | gitlab_ce | From 18.11 (inc) to 18.11.5 (exc) |
| gitlab | gitlab_ee | From 18.11 (inc) to 18.11.5 (exc) |
| gitlab | gitlab_ce | From 19.0 (inc) to 19.0.2 (exc) |
| gitlab | gitlab_ee | From 19.0 (inc) to 19.0.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-153 | The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as substitution characters when they are sent to a downstream component. |