Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

CVE-2026-19478 -- CVSS 9.4 Vulnerability Briefing

CVE-2026-19478 | CVSS 9.4 (Critical) | Exploit: PoC available

What Is It

CVE-2026-19478 is a critical unauthenticated authorization bypass in GitLab Community Edition and Enterprise Edition that can be triggered through a GraphQL directive to modify or delete public projects and user data remotely.

Technical Detail

The flaw affects GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Under certain conditions, an unauthenticated attacker can use a GraphQL directive to bypass expected authorization controls against public-project resources. Successful exploitation can result in unauthorized modification or deletion of public projects and associated user data, creating a significant integrity and availability risk.

Exploitation Status

Proof-of-concept exploit code is available. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize patching affected internet-accessible GitLab CE/EE instances. Upgrade GitLab 18.2 through 18.11.10 to 18.11.11 or later, GitLab 19.0 through 19.0.7 to 19.0.8 or later, GitLab 19.1 through 19.1.5 to 19.1.6 or later, and GitLab 19.2 through 19.2.3 to 19.2.4 or later. No workaround is confirmed in the available information. Review GitLab audit events, GraphQL request logs where retained, and project activity for unexpected modifications, deletions, membership changes, or user-data changes involving public projects, particularly actions not associated with authenticated user sessions.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →