Vulnerability Details CVE-2026-16627
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 22.2%
CVSS Severity
CVSS v3 Score 7.7
Products affected by CVE-2026-16627
-
cpe:2.3:a:gitlab:gitlab:19.2.0
-
cpe:2.3:a:gitlab:gitlab:19.2.1