CVE Tools

Критический баг в GitLab уже взяли на вооружение хакеры

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedGitLab CEGitLab EE

Our summary

watchTowr has confirmed active in-the-wild exploitation of CVE-2026-19478, a critical vulnerability affecting GitLab Community Edition and Enterprise Edition. This unauthenticated GraphQL flaw, rated 9.4 on the CVSS scale, enables attackers to remotely modify or delete public projects and alter repository data without requiring credentials or user interaction.

Versions ranging from 18.2 through 18.11.11, as well as those from 19.0 up to 19.2.4, remain vulnerable until patched with the latest releases (19.2.4, 19.1.6, 19.0.8, or 18.11.11). Security experts warn that AI-driven tools have drastically reduced the time between disclosure and attack, urging administrators to immediately apply updates or restrict unauthenticated access to /api/graphql while checking logs for @gl_introduced strings.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store