CVE-2026-19478
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Early warning: exploitation observed
- Exploitation observed since Aug 19, 2026
- Not yet in the official CISA catalogue
- First attack observed 1 day after disclosure
Source: VulnCheck KEV · Sep 8, 2026 Aug 24, 2026 Aug 21, 2026 Aug 21, 2026 Aug 19, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| gitlab | gitlab | < 18.11.11 |
Related articles
VulnerabilitiesGitLab Fixes Critical GraphQL Flaw That Could Modify or Delete Projects
GitLab patches critical GraphQL vulnerability CVE-2026-19478 that could let attackers modify or delete projects. Upgrade self-managed instances immediately.
VulnerabilitiesGitLab CVE-2026-19478 Actively Exploited Days After Disclosure
Critical GitLab vulnerability CVE-2026-19478 actively exploited within days. Updates required for CE and EE versions to prevent code injection attacks.
VulnerabilitiesCritical GitLab File-Read Flaw Exploited Within a Day of Patch Disclosure
Unauthenticated GitLab flaw CVE-2026-85706 (CVSS 10) exploited within a day. Learn affected versions, detection logs and patch deadline.
This product uses the NVD API but is not endorsed or certified by the NVD.