Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-03 · updated: 2026-10-03 · tags: [incident, global] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

GitLab disclosed on 2 October a critical vulnerability in its AI Gateway — the service connecting a GitLab instance to AI models — tracked as CVE-2026-90970 and rated 9.9 on CVSS. Under certain conditions a logged-in user with Duo Agent Platform access can run commands on the gateway. The flaw is fixed in gateway versions 19.2.4, 19.3.2 and 19.4.1, and affects every release from 18.1.6 through the 19.1 line for organisations that self-host their own gateway. GitLab runs AI Gateways for customers on GitLab.com, GitLab Dedicated and self-managed instances using a GitLab-hosted gateway, and has already fixed those; only organisations hosting their own gateway need to act, though GitLab sent update guidance to those customers before the public advisory and continues to recommend an immediate upgrade. The advisory states no evidence of use-in-attacks; CISA's assessment on the CVE record lists exploitation as "none". No workaround is listed.

Attribute Detail
Sector Global (Macro)
Date 2026-10-03
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-90970