Remote Code Modification Vulnerability in GitLab CE/EE
CVE-2026-19478
9.4CRITICAL
Key Information:
Badges
๐พ Exploit Exists๐ฐ News Worthy
What is CVE-2026-19478?
A flaw in GitLab CE/EE allows unauthenticated users to exploit specific GraphQL directives, potentially resulting in unauthorized modification or deletion of public projects and user data. This vulnerability impacts various versions, necessitating immediate user awareness and prompt application of security patches to mitigate risks associated with unauthorized access.
Affected Version(s)
GitLab 18.2 < 18.11.11
GitLab 19.0 < 19.0.8
GitLab 19.1 < 19.1.6
News Articles
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab patches CVE-2026-19478, a CVSS 9.4 GraphQL flaw that could let unauthenticated attackers modify or delete public project and user data
2 hours ago
References
CVSS V3.1
Score:
9.4
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
Credit
Thanks [hiimguardian](https://hackerone.com/hiimguardian) for reporting this vulnerability through our HackerOne bug bounty program