Remote Code Modification Vulnerability in GitLab CE/EE
CVE-2026-19478
Key Information:
Badges
What is CVE-2026-19478?
CVE-2026-19478 is a significant vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE), versions ranging from 18.2 to prior to 18.11.11, 19.0 to prior to 19.0.8, 19.1 to prior to 19.1.6, and 19.2 to prior to 19.2.4. This vulnerability allows unauthenticated users to remotely modify or delete public projects and user data through a flaw in the GraphQL directive. As GitLab is commonly utilized by organizations for version control, collaboration, and DevOps processes, this vulnerability poses a severe risk to data integrity and operational continuity. An attacker leveraging this flaw could manipulate project data or remove critical repositories, leading to loss of valuable work, disruption of services, and potential reputational damage.
Potential impact of CVE-2026-19478
-
Data Loss: Unauthorized users can delete crucial project data or repositories, resulting in irretrievable loss of intellectual property and project work that may not be easily restored or backed up.
-
Operational Disruption: The ability to modify public projects can lead to alterations in project settings or configurations, causing interruptions in collaboration workflows and hindering development processes.
-
Reputational Damage: Organizations suffering from the consequences of this vulnerability may face reputational harm due to the perceived inability to protect critical data, potentially impacting client trust and future business opportunities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitLab 18.2 < 18.11.11
GitLab 19.0 < 19.0.8
GitLab 19.1 < 19.1.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks
GitLab admins are urged to patch CVE-2026-19478 as attackers exploit the critical unauthenticated code injection flaw.I prefer this response
3 weeks ago

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - SwapUpdate
Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security
3 weeks ago
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under certain conditions.
3 weeks ago
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved