AI description
CVE-2026-19478 is a code injection vulnerability found in the GraphQL API of GitLab Community Edition (CE) and Enterprise Edition (EE). This flaw allows remote, unauthenticated attackers to send specially crafted GraphQL directives to vulnerable instances. The successful exploitation of this vulnerability can lead to the modification or deletion of public projects and associated user data. The attack requires no authentication or user interaction, making it straightforward for any actor with network access to the target instance to exploit. The vulnerability affects self-managed GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab released patches on August 17, 2026, with fixes available in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. GitLab.com and GitLab Dedicated instances are not affected, as they were already patched. The vulnerability was responsibly disclosed by security researcher hiimguardian through the HackerOne bug bounty program.
- Description
- GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
- Source
- cve@gitlab.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.4
- Impact score
- 5.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
- Severity
- CRITICAL
- cve@gitlab.com
- CWE-94
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5
CyberSignal Daily ✓ · 🛠️ DevSecOps · August 19, 2026 🎯 A CVSS 9.4 vulnerability involving one of the world's major development platforms. GitLab has patched CVE-2026-19478, a critical vulnerability rated CVSS 9.4. GitLab says that under certain conditions an unauth
@XQOPTRX
19 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-19478: Improper Control of Generation of Code ('Code Injection') in GitLab Critical Vulnerability Alert! GitLab is affected by CVE-2026-19478. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/UYgPqryQux 🔍 Identify Targets via ZoomEye: F
@zoomeye_team
19 Aug 2026
1565 Impressions
5 Retweets
17 Likes
5 Bookmarks
1 Reply
0 Quotes
GitLabの重大な脆弱性により、攻撃者が公開プロジェクトを変更または削除できる(CVE-2026-19478) Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) #HelpNetSecurity (Aug 18) https://t.co/Mzc3f0GW6z
@foxbook
19 Aug 2026
197 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
🚨 One GraphQL Directive. Two GitLab CVEs. CVE-2026-19478 (9.4): unauthenticated users can modify/delete public projects + user data CVE-2026-19650 (7.1): CSRF can execute mutations using a logged-in user’s session FULL REPORT: https://t.co/x7O2xXHq0l -- #CyberSecurity #C
@OX__Security
18 Aug 2026
340 Impressions
2 Retweets
8 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19478 - EXPLOIT CVE-2026-71518 - EXPLOIT CVE-2026-74253 CVE-2026-74843 CVE-2026-47686 ..🧵👇
@exploitgrid
18 Aug 2026
50 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Patch Now | August 18, 2026 Today's vulnerabilities are as follows; - GitLab (CVE-2026-19478, CVSS 9.4) - Zoom for Windows (CVE-2026-53412, CVSS 9.8) - WordPress Forminator Forms (CVE-2026-15748, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG https://t.co/yYzCFkUhrZ
@CERT_UG
18 Aug 2026
120 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
GitLab patches two vulnerabilities in CE and EE. CVE-2026-19478 (CVSS 9.4) permits unauthenticated code injection via GraphQL directives to alter or delete public projects. CVE-2026-19650 (CVSS 7.1) enables CSRF through insufficient GraphQL multiplex query validation. Upgrade
@WorldCyberNewsX
18 Aug 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitLabに重大(Critical)な脆弱性。CVE-2026-19478はCVSSスコア9.4で、GraphQL経由で無認証で公開リポジトリを削除可能なもの。具体的に脆弱なディレクティブは非開示。GraphQLにおけるSSRFのCVE-2026-19650と併せ修正。 https://t
@__kokumoto
17 Aug 2026
703 Impressions
0 Retweets
2 Likes
2 Bookmarks
0 Replies
0 Quotes