CVE-2026-19478: Unauthenticated Manipulation in GitLab CE/EE (self-managed)

This text was generated using artificial intelligence (AI).Update August 21, 2026: GitLab has confirmed active exploitation of CVE-2026-19478 shortly after the patch releases were published. The vulnerability has been added to the CISA KEV list. See below for details.

GitLab has fixed a vulnerability in GitLab CE/EE (self-managed) that under certain conditions one unauthenticated could allow attackers to, remotely modify or delete public projects and user data. The attack vector described here involves a GraphQL Directive. According to GitLab, the CVSS score is 9.4 Specified. Source: GitLab Advisory.

Are my systems affected? Check now →