GitLab patches critical unauthenticated GraphQL code-injection flaw CVE-2026-19478 in self-managed CE and EE

GitLab released emergency security fixes for a critical flaw that could let an unauthenticated attacker modify or delete user data and public projects on affected self-managed servers. The issue, CVE-2026-19478 (CVSS 9.4), is a code-injection bug in a GraphQL directive; GitLab also fixed CVE-2026-19650, a GraphQL multiplex query handler cross-site request forgery flaw. Affected GitLab CE and EE branches include 18.2+, 19.0, 19.1, and 19.2, with fixes in 18.11.11, 19.0.8, 19.1.6, and 19.2.4.
Why it matters: Organizations running self-managed GitLab should treat this as urgent because the most serious flaw does not require an attacker to log in first. Upgrade immediately to a fixed version; GitLab.com and GitLab Dedicated users do not need to take action.

Sources

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
info@thehackernews.com (The Hacker News) 2026.08.21 98% relevant
This updates the same CVE-2026-19478 event with the key development that attackers began exploiting the flaw within days of disclosure, increasing urgency for organizations running self-managed GitLab CE and EE.
Critical GitLab Flaw Exploited Shortly After Disclosure
Ionut Arghire 2026.08.20 96% relevant
This article updates the same CVE-2026-19478 event with new evidence that exploitation attempts began roughly two days after disclosure, based on WatchTowr honeypots, and adds concrete detection guidance to hunt for requests containing '@gl_introduced'.
GitLab Patches Critical Code Injection Vulnerability
Ionut Arghire 2026.08.18 100% relevant
This article appears to be the initial report of GitLab's August 18, 2026 disclosure and patch release for CVE-2026-19478 and CVE-2026-19650.
← Back to all stories