What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials
What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials Overview Advanced Search pushes indexed data to a backing search cluster, and CVE-2026-87719 is a critical path to
What Discloses From GitLab EE CVE-2026-87719: Advanced Search Configuration and Credentials
Overview
Advanced Search pushes indexed data to a backing search cluster, and CVE-2026-87719 is a critical path to its configuration. The vulnerability is CWE-502, insecure deserialization, in GitLab Enterprise Edition, and it carries a CVSS 3.1 base score of 9.9. GitLab fixed it on 10 September 2026 in 19.3.2, 19.2.6 and 19.1.8, and backported the change to 19.0.9 and 18.11.12 on 23 September 2026.
Why configuration, not just records
A single record or repository leak is bounded. Instance configuration is not: it often includes the address of the search cluster and the credentials GitLab uses to authenticate to it. GitLab's advisory states that an attacker with the right access "could obtain Advanced Search instance configurations and sensitive credentials." That wording points at material from which an attacker can reach the search tier directly, outside the GitLab application, where controls and logging are frequently thinner.
Mechanism and conditions
The entry point is a GraphQL subscription. GitLab EE built a server-side object from a client-supplied argument without holding it to the expected type, so a "specially crafted" argument bypassed serialization and triggered a server object lookup. The vulnerability requires an authenticated EE account with Duo Chat access; the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H confirms the low privilege bar, the absence of user interaction and the scope change across a trust boundary.
Affected versions
Only Enterprise Edition is listed:
- 18.3 before 18.11.12
- 19.0 before 19.0.9
- 19.1 before 19.1.8
- 19.2 before 19.2.6
- 19.3 before 19.3.2 GitLab.com and GitLab Dedicated are already fixed.
Exposure context
ZoomEye reports 1,326,958 instances matching app="GitLab". This is a product fingerprint, not a confirmed count of vulnerable EE servers, and administrators should treat it as guidance on how common the software is rather than as a measure of active risk. The CVE-targeted query vul.cve="CVE-2026-87719" returned 0.
Remediation and follow-up
Upgrade to 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 or later. Because the exposure concerns credentials, treat rotation as part of the fix, not an optional extra: rotate the secrets that GitLab uses for Advanced Search, then audit the search cluster for logins that did not originate from the GitLab host. Where the upgrade must wait, reduce Duo Chat access and review which accounts can reach the GraphQL endpoint.
References
- GitLab Critical Patch Release: 19.0.9, 18.11.12
- NVD record for CVE-2026-87719 (CWE-502, CVSS 9.9)
- CERT-FR advisory CERTFR-2026-AVI-1242
- GitLab work item 628160
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.