DIRAS TAKE
Urgent: public exploit code exists, so update immediately to a fixed release listed below or block access to affected instances until patched.
What is CVE-2026-19478?
Unauthenticated attackers can alter or delete public projects and user data on GitLab by abusing a flaw in GraphQL directive handling, resulting in remote code execution or data tampering (CVE-2026-19478). The issue affects GitLab releases: 18.2 up to but not including 18.11.11, 19.0 up to 19.0.8, 19.1 up to 19.1.6, and 19.2 up to 19.2.4. Exploitation requires only network access to a vulnerable GitLab instance and does not require a valid account or user interaction under the reported conditions.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Which versions of GitLab GitLab are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 18.x | 18.2 – before 18.11.11 | 18.11.11 |
| 19.x | 19.0 – before 19.0.8 | 19.0.8 |
| 19.x | 19.1 – before 19.1.6 | 19.1.6 |
| 19.x | 19.2 – before 19.2.4 | 19.2.4 |
Is CVE-2026-19478 being exploited?
Public exploit code is available for CVE-2026-19478.
How to fix CVE-2026-19478
- Upgrade GitLab to 18.11.11, 19.0.8, 19.1.6, or 19.2.4 as appropriate for your branch.
- If you cannot patch immediately, restrict network exposure to GitLab and allow access only from trusted networks.
- Enable comprehensive logging and monitor GraphQL requests and project modification activity for signs of abuse.
Frequently asked questions
Is CVE-2026-19478 being actively exploited?
Public exploit code is available for CVE-2026-19478, indicating a heightened risk of active exploitation.
Which GitLab versions are affected by CVE-2026-19478?
GitLab versions 18.2 up to 18.11.11 (exclusive), 19.0 up to 19.0.8 (exclusive), 19.1 up to 19.1.6 (exclusive), and 19.2 up to 19.2.4 (exclusive) are affected.
Is there a patch for CVE-2026-19478?
Yes. Fixed releases are 18.11.11, 19.0.8, 19.1.6, and 19.2.4 — upgrade to the appropriate fixed version for your branch.
Does CVE-2026-19478 require authentication?
No. The vulnerability can be triggered by an unauthenticated user if the GitLab instance is reachable over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-19478
- cve.org/CVERecord?id=CVE-2026-19478
- gitlab.com/gitlab-org/gitlab/-/work_items/611377
- hackerone.com/reports/3926431
- docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released
- All GitLab CVEs on CVE Radar
- CVEs published in September 2026