Critical severity9.4NVD Advisory· Published Aug 17, 2026· Updated Sep 2, 2026
CVE-2026-19478
CVE-2026-19478
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4
- Range: from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4
Patches
Vulnerability mechanics
References
2- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/nvdVendor Advisory
- hackerone.com/reports/3926431nvdPermissions Required
News mentions
15- Maximum Severity GitLab Flaw Puts Supply Chains at RiskDark Reading · Sep 14, 2026
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After DisclosureThe Hacker News · Sep 11, 2026
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Hacker News · Aug 24, 2026
- 24th August – Threat Intelligence ReportCheck Point Research · Aug 24, 2026
- Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgsHelp Net Security · Aug 23, 2026
- Critical GitLab Code Injection Vulnerability Actively Exploited in AttacksCyber Security News · Aug 21, 2026
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of DisclosureThe Hacker News · Aug 21, 2026
- Critical GitLab Flaw Exploited Shortly After DisclosureSecurityWeek · Aug 20, 2026
- GitLab Code Injection Flaw Exploited in the WildGovInfoSecurity · Aug 19, 2026
- Critical GitLab Zero-Click Flaw Poses Mitigation ChallengesDark Reading · Aug 18, 2026
- Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)Help Net Security · Aug 18, 2026
- GitLab Patches Critical Code Injection VulnerabilitySecurityWeek · Aug 18, 2026
- Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public ProjectsCyber Security News · Aug 18, 2026
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsThe Hacker News · Aug 17, 2026
- GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11GitLab Security Releases · Aug 17, 2026