CVE-2026-19478: Unauthenticated Manipulation in GitLab CE/EE (self-managed)
This text was generated using artificial intelligence (AI).Update August 21, 2026: GitLab has confirmed active exploitation of CVE-2026-19478 shortly after the patch releases were published. The vulnerability has been added to the CISA KEV list. See below for details.
GitLab has fixed a vulnerability in GitLab CE/EE (self-managed) that under certain conditions one unauthenticated could allow attackers to, remotely modify or delete public projects and user data. The attack vector described here involves a GraphQL Directive. According to GitLab, the CVSS score is 9.4 Specified. Source: GitLab Advisory.
Status: Active exploitation confirmed; CISA KEV listing
Patch available since: August 17, 2026
Affected Versions and Fixed Versions
According to the advisory, GitLab lists the following affected areas (self-managed GitLab CE/EE):
>= 18.2 and < 18.11.11
>= 19.0 and < 19.0.8
>= 19.1 and < 19.1.6
>= 19.2 and < 19.2.4
The following are listed as patched versions:
18.11.11
19.0.8
19.1.6
19.2.4
Source: GitLab (Advisory/Work Item and Patch Release Documentation).
Operational Relevance: Why This Gap Should Be Prioritized
For security, platform, and DevOps teams, the combination of Remote Attack, lacks the required privileges (PR:N) and No user interaction (UI:N) a clear indication of high priority. The CVSS vector also indicates Significant impact on integrity and availability (I:H/A:H) ...
The vulnerability is being actively exploited. GitLab reports in its latest updates that CVE-2026-19478 was observed in the wild shortly after the patch releases were published. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) list. The prioritization is therefore based on Confirmed active exploitation, attack vector, privilege level, and potential impact as well as the fact that Patch Releases Available are.
Organizations in Germany and Austria that operate GitLab CE/EE in a self-managed configuration within environments subject to NIS 2 requirements should promptly document the patch status and escalate the issue internally. For organizations in Switzerland, the revised Information Security Act (ISG) applies analogously, including the obligation to report to BACS. If an exploitation results in a personal data breach, the GDPR reporting obligation under Article 33 applies (72-hour deadline for reporting to the competent supervisory authority).
Source: GitLab.
Patch Strategy (Self-Managed): Approach Based on Release Branches
GitLab provides fixes as patch releases for multiple release branches. In practical terms, this means:
Check for impact: Is the version of GitLab CE/EE you are using within one of the ranges listed?
Upgrade in the branch being used: Upgrade to 18.11.11, 19.0.8, 19.1.6 or 19.2.4 (depending on the branch).
Prioritization by Exposure: Prioritize systems that are externally accessible and relevant to public projects. Given that active exploitation has been confirmed, this matter requires the highest priority.
Documentation: Keep a clear record of patch status and implementation.
GitLab also provides the following guidelines: GitLab.com instances have already been patched according to the standard vendor procedure; GitLab Dedicated-Customers would typically not need to take any action.
Source: GitLab.
EASM and VRM Perspectives on CVE-2026-19478
When it comes to vulnerabilities in self-hosted platforms such as GitLab, the actual risk often depends on, Which instances are visible externally at all? (e.g., under an organization’s own domain) and therefore constitute a surface area for attacks. GitLab CE/EE can typically be fingerprinted externally (e.g., via HTTP banners or version disclosure) and is often run under customer-owned domains—not infrequently on subdomains or in cloud environments that are not fully accounted for in the central asset inventory.
External Attack Surface Management (EASM) helps to, Exposed GitLab Instances systematically identify them—including those operating as shadow IT or forgotten deployments—and take them into account when prioritizing patches. Given the confirmed active exploitation of CVE-2026-19478, it is particularly critical to identify all exposed instances. In addition, Vendor Risk Management (VRM) can help clarify responsibilities and implementation approaches when operations or updates are carried out by third parties.
LocateRisk is Made in Germany and designed to be GDPR-compliant; operations take place exclusively in certified German data centers, with no data transferred to U.S. service providers.
Am I affected?
The affected versions of GitLab are those listed above; the vulnerability was fixed in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4. If you want to know whether GitLab is even visible on your own externally accessible infrastructure, you can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
According to GitLab, all self-managed CE/EE installations in versions >= 18.2 and < 18.11.11, >= 19.0 and < 19.0.8, >= 19.1 and < 19.1.6 sowie >= 19.2 and < 19.2.4. Versions prior to 18.2 are not listed as affected in the current advisory.
No — according to GitLab's standard patching schedule, GitLab.com instances have already been updated to the patched version. GitLab Dedicated customers typically do not need to take any action either. Action is required only for operators of self-managed GitLab CE/EE installations.
GitLab has confirmed active exploitation of CVE-2026-19478 shortly after the patch releases were published. CISA has added the vulnerability to the KEV list. The CVSS score of 9.4 and the attack vector (network-based, no attacker account required, no user interaction), combined with confirmed active exploitation, warrant the highest priority. An immediate upgrade to one of the patched versions is strongly recommended.
Inclusion on the CISA Known Exploited Vulnerabilities (KEV) list indicates that the vulnerability is being actively exploited by attackers. U.S. federal agencies are subject to a mandatory patch deadline. Even outside the U.S., inclusion on the KEV list is considered a clear signal of the highest urgency for applying the patch. Organizations should treat CVE-2026-19478 as a critical threat and prioritize patching efforts.
As of August 21, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked vendor advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2026-19478
Passive Assessment
Information About the CVEfound or not found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.