Critical GitLab Flaw Exploited Shortly After Disclosure
Reported exploitedGitLab CEGitLab EEOur summary
WatchTowr has confirmed that threat actors began actively exploiting CVE-2026-19478, a critical code injection flaw in GitLab Community Edition (CE) and Enterprise Edition (EE), just two days after its public disclosure. The vulnerability allows unauthenticated attackers to remotely manipulate public projects, including deleting repositories and forging merge records, without requiring any prior credentials. Users are urged to update to fixed versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, or mitigate risk by restricting access to the /api/graphql endpoint.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.