A critical security flaw in GitLab (CVE-2026-19478) allows remote attackers to manipulate or delete projects and user data without authentication. This code-injection vulnerability affects various self-managed versions of GitLab and carries a CVSS score of 9.4. Additionally, CVE-2026-19650 presents a CSRF issue with a lower severity score of 7.1.
Organizations using self-managed versions are urged to update immediately to the latest patches, as the lack of technical details complicates detection of exploit attempts. Security experts advise focusing on unusual API requests and limiting external access to mitigate risks.