GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
GitLab vulnerability exploited within days, watchTowr reports active exploitation. Fixes released in patched versions.
Intelligence analysis by Qwen 2.5 (3B)

GitLab CVE-2026-19478 flaw allows unauthenticated attackers to modify or delete projects without credentials. WatchTowr observes exploitation and recommends monitoring web logs for signs of probes.
A flaw was found in GitLab that lets bad guys change or delete projects without needing a password, which could be used to steal data.
Analysis
{"#vulnerability_details":"CVE-2026-19478 is a code injection flaw with a CVSS score of 9.4. It affects GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 to 19.2.4.","#exploitation_details":"The vulnerability can be exploited via a GraphQL directive, allowing attackers to modify or delete public projects without credentials.","#mitigation_and_response":"GitLab released fixes in version 19.2.4 and later. Organizations should monitor web logs for signs of exploitation and consider restricting unauthenticated access to '/api/graphql' or removing public repository access."}
Key points
- CVE-2026-19478 affects GitLab versions from 18.2 to 19.2.4
- The vulnerability can be exploited via a GraphQL directive
- WatchTowr observed active exploitation within days of disclosure
Timely patching can prevent exploitation. Organizations should monitor for signs of attack and apply updates as soon as possible.
If not patched quickly, attackers could use this flaw to delete projects or even entire repositories, causing significant damage.


