Remote Code Modification Vulnerability in GitLab CE/EE
CVE-2026-19478

9.4CRITICAL

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
17 August 2026

Badges

📈 Trended📈 Score: 10,100👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-19478?

CVE-2026-19478 is a significant vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE), versions ranging from 18.2 to prior to 18.11.11, 19.0 to prior to 19.0.8, 19.1 to prior to 19.1.6, and 19.2 to prior to 19.2.4. This vulnerability allows unauthenticated users to remotely modify or delete public projects and user data through a flaw in the GraphQL directive. As GitLab is commonly utilized by organizations for version control, collaboration, and DevOps processes, this vulnerability poses a severe risk to data integrity and operational continuity. An attacker leveraging this flaw could manipulate project data or remove critical repositories, leading to loss of valuable work, disruption of services, and potential reputational damage.

Potential impact of CVE-2026-19478

  1. Data Loss: Unauthorized users can delete crucial project data or repositories, resulting in irretrievable loss of intellectual property and project work that may not be easily restored or backed up.

  2. Operational Disruption: The ability to modify public projects can lead to alterations in project settings or configurations, causing interruptions in collaboration workflows and hindering development processes.

  3. Reputational Damage: Organizations suffering from the consequences of this vulnerability may face reputational harm due to the perceived inability to protect critical data, potentially impacting client trust and future business opportunities.

Affected Version(s)

GitLab 18.2 < 18.11.11

GitLab 19.0 < 19.0.8

GitLab 19.1 < 19.1.6

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks

GitLab admins are urged to patch CVE-2026-19478 as attackers exploit the critical unauthenticated code injection flaw.I prefer this response

3 weeks ago

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - SwapUpdate

Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

3 weeks ago

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under certain conditions.

3 weeks ago

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [hiimguardian](https://hackerone.com/hiimguardian) for reporting this vulnerability through our HackerOne bug bounty program
.