CVE-2026-92530 Overview
CVE-2026-92530 is an authorship spoofing vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). The flaw affects Direct Transfer imports and allows an authenticated user to attribute merge request content to arbitrary existing users on the target instance. The root cause is improper reliance on ephemeral cache state during the import process, classified under [CWE-348] Use of Less Trusted Source. GitLab remediated the issue in versions 19.2.7, 19.3.3, and 19.4.1.
Critical Impact
Authenticated attackers can spoof merge request authorship and impersonate legitimate contributors, undermining code review integrity and audit trails.
Affected Products
- GitLab CE/EE versions 19.1 up to (but not including) 19.2.7
- GitLab CE/EE versions 19.3 up to (but not including) 19.3.3
- GitLab CE/EE versions 19.4 up to (but not including) 19.4.1
Discovery Timeline
- 2026-09-24 - CVE-2026-92530 published to the National Vulnerability Database (NVD)
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-92530
Vulnerability Analysis
The vulnerability resides in GitLab's Direct Transfer import functionality. Direct Transfer moves projects and groups between GitLab instances, including merge requests and their associated metadata. During this process, the import logic references ephemeral cache state to resolve the identity mapping of merge request authors on the destination instance.
An authenticated user can manipulate conditions during the import so that cached identity data resolves to arbitrary existing users. The result is a merge request whose displayed author does not correspond to the actor who created it. This misattribution persists on the merge request record and appears authentic to reviewers.
Root Cause
The defect maps to [CWE-348] Use of Less Trusted Source. GitLab's import pipeline trusted cache entries that were populated during the import session without validating that the associated user identity was authoritative. Because the cache state is ephemeral and influenceable within the import flow, an attacker can steer the resolution toward a chosen target user.
Attack Vector
Exploitation requires an authenticated account with permission to initiate a Direct Transfer import. The attacker constructs an import payload that triggers the cache-based author resolution path. The imported merge request is then attributed to an existing user selected by the attacker. No user interaction from the impersonated victim is required. This vulnerability does not impact confidentiality or availability; impact is limited to integrity of authorship metadata.
No public proof-of-concept code is available. See the GitLab Patch Release 19.4.1 advisory and GitLab Work Item #628379 for vendor technical details.
Detection Methods for CVE-2026-92530
Indicators of Compromise
- Merge requests created through Direct Transfer imports where the recorded author did not perform the import action in audit logs.
- Import events in audit_events or application.log originating from users who subsequently do not appear as importers, but whose names surface as merge request authors.
- Unexpected Direct Transfer import jobs in bulk_imports tables targeting projects with sensitive review histories.
Detection Strategies
- Correlate GitLab audit events for bulk_import and project_import operations with the author_id field of newly created merge requests to detect mismatches.
- Alert on Direct Transfer imports followed by merge request creation attributed to users who were not the import initiator.
- Review merge request metadata for imports occurring between 2026-09-24 and the date the instance was patched.
Monitoring Recommendations
- Enable and centralize GitLab audit event streaming for import, group, and project activity.
- Track the ratio of Direct Transfer imports to distinct importer accounts and investigate outliers.
- Baseline expected importer identities and flag any Direct Transfer job that produces merge requests attributed to users outside that baseline.
How to Mitigate CVE-2026-92530
Immediate Actions Required
- Upgrade GitLab CE/EE to version 19.2.7, 19.3.3, or 19.4.1 depending on your current minor release.
- Review Direct Transfer imports performed between the vulnerable window and the patch application for spoofed authorship.
- Restrict permissions to initiate Direct Transfer imports to trusted administrators until the upgrade is complete.
Patch Information
GitLab released fixes in versions 19.2.7, 19.3.3, and 19.4.1. Refer to the GitLab Patch Release 19.4.1 announcement and GitLab Work Item #628379 for release notes and remediation details.
Workarounds
- Disable Direct Transfer imports at the instance level under Admin Area import settings until the patch is applied.
- Limit the bulk_import API and UI to a small set of vetted administrator accounts through role-based access control.
- Require secondary review of merge request authorship on any project created via Direct Transfer until upgraded.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
