📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology HIGH 5h Global apt Government/Critical Infrastructure CRITICAL 7h Global vulnerability Enterprise Software / Data Analytics CRITICAL 7h Global vulnerability Artificial Intelligence and Technology HIGH 11h Global general Technology and Artificial Intelligence MEDIUM 14h Global general Technology and Artificial Intelligence HIGH 15h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d Global supply_chain Software Development and Technology HIGH 5h Global apt Government/Critical Infrastructure CRITICAL 7h Global vulnerability Enterprise Software / Data Analytics CRITICAL 7h Global vulnerability Artificial Intelligence and Technology HIGH 11h Global general Technology and Artificial Intelligence MEDIUM 14h Global general Technology and Artificial Intelligence HIGH 15h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d Global supply_chain Software Development and Technology HIGH 5h Global apt Government/Critical Infrastructure CRITICAL 7h Global vulnerability Enterprise Software / Data Analytics CRITICAL 7h Global vulnerability Artificial Intelligence and Technology HIGH 11h Global general Technology and Artificial Intelligence MEDIUM 14h Global general Technology and Artificial Intelligence HIGH 15h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d
Vulnerabilities

CVE-2026-2370

High
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed
CWE-233 — Weakness Type
Published: Mar 30, 2026  ·  Modified: Apr 5, 2026  ·  Source: NVD
CVSS v3
8.1
🔗 NVD Official
📄 Description (English)

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and impersonate the GitLab app due to improper authorization checks.

🤖 AI Executive Summary

GitLab versions 14.3-18.8.6, 18.9.0-18.9.2, and 18.10.0 contain an authorization bypass vulnerability in Jira Connect installations that allows authenticated users with minimal workspace permissions to steal installation credentials and impersonate the GitLab application. This high-severity vulnerability (CVSS 8.1) affects both Community and Enterprise editions and could enable lateral movement and unauthorized access to integrated systems. Immediate patching to versions 18.8.7, 18.9.3, or 18.10.1+ is critical for organizations using GitLab with Jira integrations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 26, 2026 06:56
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations in software development, financial services, and government sectors using GitLab with Jira integrations face significant risk. Banking institutions (SAMA-regulated) and government agencies (NCA oversight) utilizing these platforms for DevOps pipelines could experience unauthorized access to sensitive project data, credentials, and integrated systems. Telecom operators (STC, Mobily) and energy sector organizations (ARAMCO) managing critical infrastructure code through GitLab are particularly vulnerable. The vulnerability enables privilege escalation from minimal workspace permissions to full application impersonation, potentially compromising CI/CD pipelines and deployment credentials.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Telecommunications Energy and Utilities Healthcare Software Development and Technology Defense and Security
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all GitLab instances running affected versions (14.3-18.8.6, 18.9.0-18.9.2, 18.10.0) with Jira Connect enabled
2. Audit Jira Connect installation credentials and access logs for unauthorized access attempts
3. Rotate all GitLab-to-Jira integration credentials and API tokens immediately
4. Review workspace permissions and audit user access to Jira Connect configurations

PATCHING GUIDANCE:
1. Upgrade GitLab to patched versions: 18.8.7, 18.9.3, 18.10.1 or later
2. Test patches in non-production environments before production deployment
3. Schedule maintenance windows for upgrades to minimize business disruption
4. Verify Jira Connect functionality post-upgrade

COMPENSATING CONTROLS (if immediate patching not possible):
1. Restrict Jira Connect workspace access to trusted administrators only
2. Implement network segmentation to limit GitLab-Jira communication
3. Enable MFA for all GitLab accounts with workspace permissions
4. Monitor and log all Jira Connect API calls and credential access

DETECTION RULES:
1. Alert on unauthorized access to GitLab Jira Connect installation endpoints
2. Monitor for credential extraction attempts from /api/v4/admin/integrations/jira_connect endpoints
3. Track unusual API token generation or usage patterns
4. Log all changes to Jira Connect workspace permissions and configurations
5. Detect lateral movement attempts using stolen GitLab credentials to access Jira or other integrated systems
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع مثيلات GitLab التي تعمل بالإصدارات المتأثرة (14.3-18.8.6، 18.9.0-18.9.2، 18.10.0) مع تفعيل Jira Connect
2. تدقيق بيانات اعتماد Jira Connect وسجلات الوصول لمحاولات الوصول غير المصرح به
3. تدوير جميع بيانات اعتماد التكامل بين GitLab و Jira وتوكنات API فوراً
4. مراجعة صلاحيات مساحة العمل وتدقيق وصول المستخدم إلى تكوينات Jira Connect

إرشادات التصحيح:
1. ترقية GitLab إلى الإصدارات المصححة: 18.8.7، 18.9.3، 18.10.1 أو أحدث
2. اختبار التصحيحات في بيئات غير الإنتاج قبل نشر الإنتاج
3. جدولة نوافذ الصيانة للترقيات لتقليل انقطاع الأعمال
4. التحقق من وظائف Jira Connect بعد الترقية

الضوابط البديلة (إذا لم يكن التصحيح الفوري ممكناً):
1. تقييد وصول مساحة عمل Jira Connect للمسؤولين الموثوقين فقط
2. تنفيذ تقسيم الشبكة لتحديد اتصالات GitLab-Jira
3. تفعيل MFA لجميع حسابات GitLab بصلاحيات مساحة العمل
4. مراقبة وتسجيل جميع استدعاءات Jira Connect API والوصول إلى بيانات الاعتماد

قواعد الكشف:
1. التنبيه على الوصول غير المصرح به إلى نقاط نهاية تثبيت GitLab Jira Connect
2. مراقبة محاولات استخراج بيانات الاعتماد من نقاط نهاية /api/v4/admin/integrations/jira_connect
3. تتبع أنماط توليد أو استخدام توكن API غير العادية
4. تسجيل جميع التغييرات على صلاحيات وتكوينات مساحة عمل Jira Connect
5. الكشف عن محاولات الحركة الجانبية باستخدام بيانات اعتماد GitLab المسروقة للوصول إلى Jira أو الأنظمة المدمجة الأخرى
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies (unauthorized credential access) ECC 2024 A.6.1.2 - User Registration and De-registration (privilege escalation) ECC 2024 A.8.2.1 - User Access Management (improper authorization checks) ECC 2024 A.9.2.1 - User Access Rights Review (credential theft vulnerability)
🔵 SAMA CSF
SAMA CSF ID.AM-1 - Asset Management (GitLab integration inventory) SAMA CSF PR.AC-1 - Access Control Policy (authorization bypass) SAMA CSF PR.AC-4 - Access Rights Management (minimal permissions escalation) SAMA CSF DE.CM-1 - Detection and Analysis (credential compromise monitoring)
🟡 ISO 27001:2022
ISO 27001:2022 A.5.2 - Information Security Policies (access control framework) ISO 27001:2022 A.8.2 - User Access Management (authentication and authorization) ISO 27001:2022 A.8.3 - User Responsibilities (credential protection) ISO 27001:2022 A.9.2 - User Access Rights (privilege management)
🟣 PCI DSS v4.0.1
PCI DSS 2.1 - Change default vendor-supplied passwords (GitLab credentials) PCI DSS 7.1 - Restrict access to cardholder data (authorization controls) PCI DSS 8.1 - User identification and authentication (credential compromise)
📦 Affected Products / CPE 6 entries
gitlab:gitlab
gitlab:gitlab
gitlab:gitlab
gitlab:gitlab
gitlab:gitlab:18.10.0
gitlab:gitlab:18.10.0
📊 CVSS Score
8.1
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score8.1
CWECWE-233
EPSS0.01%
Exploit No
Patch ✓ Yes
Published 2026-03-30
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
patch-available CWE-233
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.