CVE-2026-3857

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to execute arbitrary GraphQL mutations on behalf of authenticated users due to insufficient CSRF protection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*

History

30 Mar 2026, 15:19

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
CPE cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.10.0:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
Summary
  • (es) GitLab ha remediado un problema en GitLab CE/EE que afecta a todas las versiones desde la 17.10 anterior a la 18.8.7, la 18.9 anterior a la 18.9.3 y la 18.10 anterior a la 18.10.1 que podría haber permitido a un usuario no autenticado ejecutar mutaciones GraphQL arbitrarias en nombre de usuarios autenticados debido a una protección CSRF insuficiente.
References () https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/ - () https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/ - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/work_items/592828 - () https://gitlab.com/gitlab-org/gitlab/-/work_items/592828 - Broken Link
References () https://hackerone.com/reports/3584382 - () https://hackerone.com/reports/3584382 - Permissions Required

25 Mar 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 17:17

Updated : 2026-03-30 15:19


NVD link : CVE-2026-3857

Mitre link : CVE-2026-3857

CVE.ORG link : CVE-2026-3857


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-352

Cross-Site Request Forgery (CSRF)