www.securityweek.com 8/20/2026, 8:10:43 AM · external

GitLab Flaw CVE-2026-19478 Exploited in Days, Urges Patch

GitLab Flaw CVE-2026-19478 Exploited in Days, Urges Patch
Developing story vulnerability 6 articles tracked
GitLab GraphQL injection flaw (CVE-2026-19478) allows unauthenticated project modification
CyberSIXT Evidence Panel
Primary Source docs.gitlab.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical-severity vulnerability in GitLab (CVE-2026-19478) has been exploited within two days of its disclosure, allowing unauthenticated attackers to remotely modify or delete public projects and user data. The flaw, which has a CVSS score of 9.4, was patched on August 17, 2026. WatchTowr warns users to update their GitLab instances promptly and restrict access to certain endpoints to mitigate risks.

Exploiting this vulnerability could facilitate supply chain attacks by allowing attackers to forge trusted merge records. Organizations are advised to monitor logs for signs of exploitation attempts.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline