CVE-2026-2370

8.1

GitLab · GitLab CE/EE

An improper authorization flaw in GitLab Jira Connect installations allows authenticated users to obtain installation credentials and impersonate the application.

Executive summary

A vulnerability in GitLab CE/EE allows authenticated users with minimal permissions to perform credential theft and application impersonation, posing a significant risk to internal integrations.

Vulnerability

This vulnerability is an improper authorization flaw (CWE-233) within Jira Connect installations. It allows an authenticated user with minimal workspace permissions to bypass authorization checks to access installation credentials and impersonate the GitLab application.

Business impact

The ability for a low-privileged user to impersonate the GitLab application and access installation credentials could lead to unauthorized access to integrated systems, including Jira. With a CVSS score of 8.1, this high-severity flaw threatens the confidentiality and integrity of the development ecosystem and could result in lateral movement or sensitive data exposure.

Remediation

Immediate Action: Upgrade all GitLab CE/EE instances to versions 18.8.7, 18.9.3, 18.10.1, or above immediately.

Proactive Monitoring: Monitor GitLab audit logs for suspicious API calls or unauthorized attempts to access Jira Connect configuration settings.

Compensating Controls: Restrict access to Jira Connect configuration settings or disable the integration temporarily if an immediate update is not feasible.

Exploitation status

Public Exploit Available: Yes, a published PoC exists, attributed to the security researcher's write-up on HackerOne (Report 3522829).

Analyst recommendation

Given the high CVSS score and the potential for credential theft and application impersonation, this vulnerability represents a significant security risk. Organizations must prioritize the deployment of the provided patches to ensure the integrity of their GitLab and Jira integrations. Failure to update may allow malicious actors to abuse internal credentials to gain unauthorized access to connected systems.

More GitLab CVEs

Sources

Originally found and disclosed by Thanks [maksyche](https://hackerone.com/maksyche) for reporting this vulnerability through our HackerOne bug bounty prog, per the CVE Program record.