Organizations running self-hosted GitLab AI Gateway should update to the patched versions immediately: 19.2.4, 19.3.2, or 19.4.1, depending on their current release series. Apply the latest updates via the GitLab package manager or by downloading the appropriate binary from the GitLab download page. Review and restrict Duo Agent Platform access permissions as a defensive measure while updating.
Quick answers
What is CVE-2026-44951?
Organizations running self-hosted GitLab AI Gateway should update to the patched versions immediately: 19.2.4, 19.3.2, or 19.4.1, depending on their current release series. Apply the latest updates via the GitLab package manager or by downloading the appropriate binary from the GitLab download page. Review and restrict Duo Agent Platform access permissions as a defensive measure while updating.
How severe is CVE-2026-44951?
high, CVSS 9.9
Is CVE-2026-44951 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-44951 be mitigated?
Organizations running self-hosted GitLab AI Gateway should update to the patched versions immediately: 19.2.4, 19.3.2, or 19.4.1, depending on their current release series. Apply the latest updates via the GitLab package manager or by downloading the appropriate binary from the GitLab download page. Review and restrict Duo Agent Platform access permissions as a defensive measure while updating.
CVSS
9.9
Vendor
GitLab
Published
Oct 3, 2026 · 04:09
Patch
Unknown / not confirmed
Affected products
AI Gateway
Mitigation
Organizations running self-hosted GitLab AI Gateway should update to the patched versions immediately: 19.2.4, 19.3.2, or 19.4.1, depending on their current release series. Apply the latest updates via the GitLab package manager or by downloading the appropriate binary from the GitLab download page. Review and restrict Duo Agent Platform access permissions as a defensive measure while updating.
GitLab has released patches to address a critical vulnerability in its AI Gateway component, tracked as CVE-2026-44951. The flaw could allow a logged-in user with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway servers under certain conditions. The vulnerability affects GitLab AI Gateway versions prior to 19.2.4, 19.3.2, and 19.4.1. Organizations running self-hosted instances are urged to update immediately.