• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-19478: pre-auth remote code execution in GitLab GitLab

Unauthenticated attackers can alter or delete public projects and user data on GitLab by abusing a flaw in GraphQL directive handling, resulting in remote code execution or data tampering (CVE-2026-19478). The issue affects GitLab releases: 18.2 up to but not including 18.11.11, 19.0 up to 19.0.8, 19.1 up to 19.1.6, and 19.2 up to 19.2.4. Exploitation requires only network access to a vulnerable GitLab instance and does not require a valid account or user interaction under the reported conditions.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.60204
CWE
CWE-94
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so update immediately to a fixed release listed below or block access to affected instances until patched.

What is CVE-2026-19478?

Unauthenticated attackers can alter or delete public projects and user data on GitLab by abusing a flaw in GraphQL directive handling, resulting in remote code execution or data tampering (CVE-2026-19478). The issue affects GitLab releases: 18.2 up to but not including 18.11.11, 19.0 up to 19.0.8, 19.1 up to 19.1.6, and 19.2 up to 19.2.4. Exploitation requires only network access to a vulnerable GitLab instance and does not require a valid account or user interaction under the reported conditions.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Which versions of GitLab GitLab are affected?

BRANCHAFFECTEDFIXED
18.x18.2 – before 18.11.1118.11.11
19.x19.0 – before 19.0.819.0.8
19.x19.1 – before 19.1.619.1.6
19.x19.2 – before 19.2.419.2.4

Is CVE-2026-19478 being exploited?

Public exploit code is available for CVE-2026-19478.

How to fix CVE-2026-19478

  1. Upgrade GitLab to 18.11.11, 19.0.8, 19.1.6, or 19.2.4 as appropriate for your branch.
  2. If you cannot patch immediately, restrict network exposure to GitLab and allow access only from trusted networks.
  3. Enable comprehensive logging and monitor GraphQL requests and project modification activity for signs of abuse.

Frequently asked questions

Is CVE-2026-19478 being actively exploited?

Public exploit code is available for CVE-2026-19478, indicating a heightened risk of active exploitation.

Which GitLab versions are affected by CVE-2026-19478?

GitLab versions 18.2 up to 18.11.11 (exclusive), 19.0 up to 19.0.8 (exclusive), 19.1 up to 19.1.6 (exclusive), and 19.2 up to 19.2.4 (exclusive) are affected.

Is there a patch for CVE-2026-19478?

Yes. Fixed releases are 18.11.11, 19.0.8, 19.1.6, and 19.2.4 — upgrade to the appropriate fixed version for your branch.

Does CVE-2026-19478 require authentication?

No. The vulnerability can be triggered by an unauthenticated user if the GitLab instance is reachable over the network.

References