CVE-2026-19478: Critical GitLab GraphQL Flaw Enables Unauthenticated Data Modification
ID: 82e93a3c-dbd8-5230-b59f-f67d1d1f09e0
STIX ID: report--82e93a3c-dbd8-5230-b59f-f67d1d1f09e0
Feed Name: SOC Prime Blog
GitLab issued an emergency security update on August 17, 2026 to fix CVE-2026-19478, a critical (CVSS 9.4) GraphQL code injection vulnerability in self-managed GitLab CE/EE that allows unauthenticated remote attackers to modify or delete public projects and user data; GitLab provided patched releases (18.11.11, 19.0.8, 19.1.6, 19.2.4), recommended immediate upgrades, and offered detection and mitigation guidance while noting no public PoC or confirmed exploitation as of publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
