CVE Tools

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

The Hacker NewsBy The Hacker News

Reported exploitedGitLab CEGitLab EE

Our summary

WatchTowr has detected active in-the-wild exploitation of CVE-2026-19478, a critical code injection vulnerability affecting GitLab CE and EE shortly after its public disclosure. With a CVSS score of 9.4, this flaw allows unauthenticated attackers to manipulate or delete public projects via the GraphQL interface without needing credentials. Affected versions include GitLab 18.2 prior to 18.11.11, 19.0 before 19.0.8, 19.1 prior to 19.1.6, and 19.2 before 19.2.4. Organizations should upgrade to the patched releases immediately or mitigate risk by restricting unauthenticated access to /api/graphql while reviewing web logs for suspicious @gl_introduced directives.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store