CVE Tools

Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

Dark ReadingBy Jai Vijayan

PatchGitLab CE/EE

Our summary

GitLab has issued an out-of-band security update to address CVE-2026-19478, a critical code-injection vulnerability with a CVSS score of 9.4 that affects self-managed instances of GitLab Community Edition and Enterprise Edition. This flaw allows unauthenticated remote attackers to manipulate or delete public projects and user data via the platform's GraphQL interface without requiring any login credentials or user interaction. While GitLab.com and GitLab Dedicated users are already protected, organizations running self-hosted versions between 18.2 and prior 19.2.4 must immediately upgrade to fixed releases such as 18.11.11, 19.0.8, 19.1.6, or 19.2.4. The disclosure also includes a secondary CSRF bug, CVE-2026-19650, rated 7.1, which carries similar version constraints and can enable unauthorized changes via crafted requests.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store