CVE-2026-19478 -- CVSS 9.4 Vulnerability Briefing
CVE-2026-19478 | CVSS 9.4 (Critical) | Exploit: PoC available
What Is It
CVE-2026-19478 is a critical unauthenticated authorization bypass in GitLab Community Edition and Enterprise Edition that can be triggered through a GraphQL directive to modify or delete public projects and user data remotely.
Technical Detail
The flaw affects GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Under certain conditions, an unauthenticated attacker can use a GraphQL directive to bypass expected authorization controls against public-project resources. Successful exploitation can result in unauthorized modification or deletion of public projects and associated user data, creating a significant integrity and availability risk.
Exploitation Status
Proof-of-concept exploit code is available. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize patching affected internet-accessible GitLab CE/EE instances. Upgrade GitLab 18.2 through 18.11.10 to 18.11.11 or later, GitLab 19.0 through 19.0.7 to 19.0.8 or later, GitLab 19.1 through 19.1.5 to 19.1.6 or later, and GitLab 19.2 through 19.2.3 to 19.2.4 or later. No workaround is confirmed in the available information. Review GitLab audit events, GraphQL request logs where retained, and project activity for unexpected modifications, deletions, membership changes, or user-data changes involving public projects, particularly actions not associated with authenticated user sessions.