Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5816

29
FAUCET Score

CVE-2026-5816 is a cross-site scripting vulnerability affecting GitLab Community Edition and Enterprise Edition versions 18.10 before 18.10.4 and 18.11 before 18.11.1. The flaw stems from improper path validation that allows unauthenticated attackers to inject and execute arbitrary JavaScript code within a victim's browser session under specific conditions. This vulnerability requires user interaction to trigger but can result in complete compromise of session confidentiality and integrity. The vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.0, reflecting its network-accessible attack vector and requirement for user interaction. The attack has high complexity and does not require authentication, but successful exploitation depends on tricking users into performing specific actions. The potential impact includes high confidentiality and integrity violations, though availability is not affected. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The EPSS score of 0.00012 indicates extremely low probability of exploitation in real-world scenarios compared to other published CVEs. Organizations should prioritize patching to the fixed versions (18.10.4 or 18.11.1 and later) as part of routine security maintenance but need not treat this as an emergency incident response priority.

Impacted Technologies

VendorProductVersion(s)CPE
>= 18.10, < 18.10.4CPE match
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
>= 18.11, < 18.11.1CPE match
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
>= 18.10.0, < 18.10.4CPE matchmatch criteria
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
>= 18.10.0, < 18.10.4CPE matchmatch criteria
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
18.11.0CPE matchmatch criteria
cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 37th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

about.gitlab.com / releases/2026/04/22/patch-release-gitlab-18-11-1-released
Release NotesVendor Advisory
gitlab.com / gitlab-org/gitlab/-/work_items/592816
Broken Link
hackerone.com / reports/3572231
Permissions Required