PT-2026-76768 · Gitlab · Gitlab

CVE-2026-19478

·

Published

2026-08-17

·

Updated

2026-09-02

CVSS v3.1

9.7

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 18.2 through 18.11.10 GitLab CE/EE versions 19.0 through 19.0.7 GitLab CE/EE versions 19.1 through 19.1.5 GitLab CE/EE versions 19.2 through 19.2.3
Description An unauthenticated remote attacker can modify or delete public projects and user data through a code injection flaw. The issue stems from incorrect code generation management and a specially crafted GraphQL directive that bypasses standard field processing logic to affect server-side objects. This flaw has been observed under active exploitation in the wild. The attack requires HTTP(S) access to the GraphQL API endpoint.
Recommendations Update GitLab CE/EE versions 18.2 through 18.11.10 to version 18.11.11 or newer. Update GitLab CE/EE versions 19.0 through 19.0.7 to version 19.0.8 or newer. Update GitLab CE/EE versions 19.1 through 19.1.5 to version 19.1.6 or newer. Update GitLab CE/EE versions 19.2 through 19.2.3 to version 19.2.4 or newer. Restrict access to the GraphQL API for untrusted sources using a reverse proxy, WAF, or VPN. Limit GitLab access from external networks as a temporary measure.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11879
BIT-GITLAB-2026-19478
CVE-2026-19478

Affected Products

Gitlab