CVE-2026-19478

Published Aug 17, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-19478 is a code injection vulnerability found in the GraphQL API of GitLab Community Edition (CE) and Enterprise Edition (EE). This flaw allows remote, unauthenticated attackers to send specially crafted GraphQL directives to vulnerable instances. The successful exploitation of this vulnerability can lead to the modification or deletion of public projects and associated user data. The attack requires no authentication or user interaction, making it straightforward for any actor with network access to the target instance to exploit. The vulnerability affects self-managed GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab released patches on August 17, 2026, with fixes available in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. GitLab.com and GitLab Dedicated instances are not affected, as they were already patched. The vulnerability was responsibly disclosed by security researcher hiimguardian through the HackerOne bug bounty program.

Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Source
cve@gitlab.com
NVD status
Analyzed
Products
gitlab

Risk scores

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@gitlab.com
CWE-94

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2026-19478 affects GitLab GraphQL and can let unauthenticated users modify or delete public projects. Explore SIEM, Sigma and audit-log detection techniques. #GitLab #CVE https://t.co/5IKgPkhwE9 https://t.co/OixMD3WvOc

    @ShellCodeXHQ

    10 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [GITLAB] — CVE-2026-19478: un atacante sin cuenta puede borrar o modificar proyectos públicos. Impacto: instancias self-managed de GitLab CE/EE (ramas 18.2 a 19.2) permiten a un atacante no autenticado alcanzar mutaciones GraphQL que borran o cambian proyectos públicos y dat

    @Soy_Nube_Negra

    30 Aug 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. GitLab GraphQL の脆弱性 CVE-2026-19478 が FIX:公開プロジェクトの変更/削除が可能 https://t.co/PSZDg7elOe 開発支援ツールである GitLab CE/EE の緊急アップデート情報を解説する投稿です。通常スケジュール外で速報が提

    @iototsecnews

    25 Aug 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Critical CVEs (Aug 24): Windows DNS Server RCE (CVE-2026-62878) & GitLab code injection (CVE-2026-19478) threaten data privacy/integrity in transit. Patch urgently! #Cybersecurity #ZeroDay #NetworkSecurity

    @YourAnon_irc

    24 Aug 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-19478:GitLabの脆弱性が実環境で悪用され、概念実証(PoC)が公開されました CVE-2026-19478: GitLab Flaw Exploited in the Wild, PoC Public #DailyCyberSecurity (Aug 23) https://t.co/e3rMwAGSdz

    @foxbook

    24 Aug 2026

    267 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. GitLabの脆弱性CVE-2026-19478が公表後わずか数日で悪用される GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure #HackerNews (Aug 21) https://t.co/yj9iGcDtH8

    @foxbook

    24 Aug 2026

    337 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CVE-2026-19478 — Critical GitLab GraphQL Vulnerability CVSS 9.4 • No authentication required • Self-managed GitLab CE/EE affected • https://t.co/WHsqSShFhj #CVE #CVE202619478 #GitLab #GraphQL #CyberSecurity #InfoSec #Vulnerability #Exploit #DevSecOps

    @stem__shop

    24 Aug 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. GitLab's CVE-2026-19478 code injection flaw is under active exploitation days after disclosure, alongside a max-severity Microsoft Entra ID vulnerability. https://t.co/kimdCxmyvk

    @threatcluster

    23 Aug 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. ⚡ GitLab CVE-2026-19478 (CVSS 9.4) actively exploited within days of disclosure. Patches available for 18.11.11+ / 19.0.8+. If you run self-hosted GitLab, update NOW. 🔗 https://t.co/Y2swQJYTS8

    @CyberOSINTIO

    23 Aug 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Opening public the lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced ) , since it's already around. This is a 'safe env setup' https://t.co/0R0HbzTTdQ

    @Dinosn

    23 Aug 2026

    5536 Impressions

    13 Retweets

    61 Likes

    32 Bookmarks

    1 Reply

    0 Quotes

  11. GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure https://t.co/hJvSIC4qlY

    @PVynckier

    23 Aug 2026

    189 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 GitLab #CVE-2026-19478: A Critical Zero-Click Risk Puts Public Projects and User Data in the Crosshairs + Video -Fact Checker: ✅: 4 ❌: 1 || 4/5 → Score: 80% 🦾 -Prediction: 📈 4 Positive | 📉 2 Negative https://t.co/jW7Gx9KHjQ

    @undercode_news

    23 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Critical GitLab GraphQL flaw (CVE-2026-19478, CVSS 9.4) is under active exploitation days after disclosure. Unauthenticated attackers can modify or delete public projects. Self-managed instances: patch to 19.2.4+ immediately and audit GraphQL activity. #CyberSecurity

    @Lumideezy

    22 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 ALERTA | GitLab bajo explotación activa CVE-2026-19478 (CVSS 9.4) está siendo explotada activamente y puede permitir a atacantes no autenticados modificar o eliminar proyectos públicos. ⚠️ Instancias self-managed: actualización inmediata. #CyberSecurity #GitLab #C

    @Bussio28Team

    22 Aug 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2026-19478 (CVSS 9.4) lets unauthenticated attackers turn a GitLab GraphQL query into an arbitrary method call. watchTowr reproduced it in minutes from the patch diff, and exploitation in the wild started 2 days later. Public PoC exists. Patch self-managed GitLab now. https:/

    @SynScanNet

    22 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. Max-severity Entra ID RCE (CVE-2026-69836) and GitLab CVE-2026-19478 are both under active exploitation, while a poisoned arrayref Rust crate slips build-time malware into the supply chain. #CyberSecurity #BlueTeam #SupplyChain https://t.co/w2LglIfVuf

    @itsalreadywhen

    21 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 🚨 GitLab Alert 🚨 CVE-2026-19478 (CVSS 9.4) is reportedly being actively exploited, putting public projects and data at risk. 🔐 Patch your GitLab instances now. #CyberSecurity #GitLab #CVE #InfoSec

    @Securium_academ

    21 Aug 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. GitLab ships emergency patch for critical GraphQL code-injection flaw (CVE-2026-19478, CVSS 9.4) — GitLab issued an out-of-band release to fix CVE-2026-19478, a critical code-injection flaw in a… #CyberSecurity #InfoSec https://t.co/HL8EDiAxWp

    @JNitterauer

    20 Aug 2026

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. CyberSignal Daily ✓ · 🛠️ DevSecOps · August 19, 2026 🎯 A CVSS 9.4 vulnerability involving one of the world's major development platforms. GitLab has patched CVE-2026-19478, a critical vulnerability rated CVSS 9.4. GitLab says that under certain conditions an unauth

    @XQOPTRX

    19 Aug 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 CVE-2026-19478: Improper Control of Generation of Code ('Code Injection') in GitLab Critical Vulnerability Alert! GitLab is affected by CVE-2026-19478. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/UYgPqryQux 🔍 Identify Targets via ZoomEye: F

    @zoomeye_team

    19 Aug 2026

    1565 Impressions

    5 Retweets

    17 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  21. GitLabの重大な脆弱性により、攻撃者が公開プロジェクトを変更または削除できる(CVE-2026-19478) Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) #HelpNetSecurity (Aug 18) https://t.co/Mzc3f0GW6z

    @foxbook

    19 Aug 2026

    197 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  22. 🚨 One GraphQL Directive. Two GitLab CVEs. CVE-2026-19478 (9.4): unauthenticated users can modify/delete public projects + user data CVE-2026-19650 (7.1): CSRF can execute mutations using a logged-in user’s session FULL REPORT: https://t.co/x7O2xXHq0l -- #CyberSecurity #C

    @OX__Security

    18 Aug 2026

    340 Impressions

    2 Retweets

    8 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19478 - EXPLOIT CVE-2026-71518 - EXPLOIT CVE-2026-74253 CVE-2026-74843 CVE-2026-47686 ..🧵👇

    @exploitgrid

    18 Aug 2026

    50 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  24. 🚨 Patch Now | August 18, 2026 Today's vulnerabilities are as follows; - GitLab (CVE-2026-19478, CVSS 9.4) - Zoom for Windows (CVE-2026-53412, CVSS 9.8) - WordPress Forminator Forms (CVE-2026-15748, CVSS 9.8) https://t.co/fR71dyoG2H | #CyberSafeUG https://t.co/yYzCFkUhrZ

    @CERT_UG

    18 Aug 2026

    120 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. GitLab patches two vulnerabilities in CE and EE. CVE-2026-19478 (CVSS 9.4) permits unauthenticated code injection via GraphQL directives to alter or delete public projects. CVE-2026-19650 (CVSS 7.1) enables CSRF through insufficient GraphQL multiplex query validation. Upgrade

    @WorldCyberNewsX

    18 Aug 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. GitLabに重大(Critical)な脆弱性。CVE-2026-19478はCVSSスコア9.4で、GraphQL経由で無認証で公開リポジトリを削除可能なもの。具体的に脆弱なディレクティブは非開示。GraphQLにおけるSSRFのCVE-2026-19650と併せ修正。 https://t

    @__kokumoto

    17 Aug 2026

    703 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

Configurations