CVE Tools

Critical GitLab Flaw Exploited Shortly After Disclosure

SecurityWeekBy Ionut Arghire

Reported exploitedGitLab CEGitLab EE

Our summary

WatchTowr has confirmed that threat actors began actively exploiting CVE-2026-19478, a critical code injection flaw in GitLab Community Edition (CE) and Enterprise Edition (EE), just two days after its public disclosure. The vulnerability allows unauthenticated attackers to remotely manipulate public projects, including deleting repositories and forging merge records, without requiring any prior credentials. Users are urged to update to fixed versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, or mitigate risk by restricting access to the /api/graphql endpoint.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store