Critical GitLab Flaw Exploited Shortly After Disclosure

https://www.securityweek.com/wp-content/uploads/2026/06/GitLab.jpeg

Threat actors started exploiting a critical-severity GitLab vulnerability roughly two days after public disclosure, attack surface management company WatchTowr warns.

Tracked as CVE-2026-19478 (CVSS score of 9.4), the code injection defect was patched on August 17, when GitLab warned that it could be exploited remotely without authentication.

“GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive,” GitLab said.

Fixes were rolled out in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

On August 18, WatchTowr warned that the flaw could be easily reproduced, urging users to update their self-managed instances as soon as possible. As a mitigation, they should restrict unauthenticated access to the /api/graphql endpoint or remove public repository access entirely.

“Whilst no public exploit code is available, WatchTowr was able to...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more