logo

CVE-2026-19478: Critical GitLab GraphQL Flaw Enables Unauthenticated Data Modification

ID: 82e93a3c-dbd8-5230-b59f-f67d1d1f09e0

STIX ID: report--82e93a3c-dbd8-5230-b59f-f67d1d1f09e0

Feed Name: SOC Prime Blog

Threat Score
78/100

Date Published: 2026-08-19

Date Updated: 2026-08-24

Author: SOC Prime Team

...
...

GitLab issued an emergency security update on August 17, 2026 to fix CVE-2026-19478, a critical (CVSS 9.4) GraphQL code injection vulnerability in self-managed GitLab CE/EE that allows unauthenticated remote attackers to modify or delete public projects and user data; GitLab provided patched releases (18.11.11, 19.0.8, 19.1.6, 19.2.4), recommended immediate upgrades, and offered detection and mitigation guidance while noting no public PoC or confirmed exploitation as of publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.