CVE-2026-19478

Critical9.4Published on August 17, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Early warning: exploitation observed

  • Exploitation observed since Aug 19, 2026
  • Not yet in the official CISA catalogue
  • First attack observed 1 day after disclosure

Source: VulnCheck KEV · Sep 8, 2026 Aug 24, 2026 Aug 21, 2026 Aug 21, 2026 Aug 19, 2026

CVSS score9.4 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Weakness type (CWE)CWE-94
Vendorsgitlab

Affected products

VendorsProductVersions
gitlabgitlab< 18.11.11

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database