Critical GitLab GraphQL Flaw Is Under Active Exploitation Days After Patch
GitLab patched CVE-2026-19478, a critical unauthenticated GraphQL code-injection flaw, and exploitation attempts were reported within days of disclosure.
Why it matters: The flaw affects self-managed GitLab infrastructure used in software supply chains, requires no authentication under affected conditions, and reportedly moved into exploitation within days of disclosure.
A critical GitLab vulnerability that can allow unauthenticated attackers to modify or delete public projects has come under reported active exploitation only days after the company released emergency patches.
The vulnerability, CVE-2026-19478, carries a CVSS severity score of 9.4 and affects multiple versions of self-managed GitLab Community Edition and Enterprise Edition. GitLab released fixes in versions 18.11.11, 19.0.8, 19.1.6 and 19.2.4 on August 17.
GitLab says the flaw can, under certain conditions, allow an unauthenticated attacker to remotely modify or delete public projects and user data through a GraphQL directive. GitLab.com and GitLab Dedicated are already running patched software.
Security organizations subsequently reported exploitation attempts in the wild, sharply reducing the practical window for administrators to patch exposed self-managed instances.
The potential consequences extend beyond availability. Unauthorized project modification can undermine source-code integrity and create software-supply-chain risk for organizations that rely on GitLab repositories and CI/CD workflows.
GitLab strongly recommends that affected self-managed installations upgrade immediately. The episode is another example of how quickly public vulnerability disclosures can move from patch release to attempted weaponization.