logo

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

ID: dd24d92a-d511-50ec-8a1c-4baf5ab6f2ef

STIX ID: report--dd24d92a-d511-50ec-8a1c-4baf5ab6f2ef

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-08-18

Date Updated: 2026-08-19

Author: Sinisa Markovic

...
...

GitLab released patches for two vulnerabilities affecting multiple CE/EE versions: CVE-2026-19478 (CVSS 9.4) is a critical unauthenticated code-injection via a GraphQL directive that could let attackers modify or delete public projects and user data, and CVE-2026-19650 (CVSS 7.1) is a CSRF issue in the GraphQL multiplex handler that may allow executing mutations via GET with user interaction; fixes are available in 19.2.4, 19.1.6, 19.0.8 and 18.11.11 and GitLab.com has already been patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.