CVE-2026-19478Active Exploitation(gitlab / gitlab)

CRITICALCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 47 mentions and remains active

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Active exploitation appears in 73 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 173 mentions across 16 observed days

What's happening

  • Active exploitation reported across 73 signals
  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 23 signals
  • Patch or workaround mentioned in 101 signals
  • Technical details provided in 111 signals
  • Disclosure: 24 classified signals
  • Peaked 14d ago at 47 mentions (2026-08-18); latest day: 1
  • 173 total mentions across 16 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline173 mentions / 16d
012243547Mentions · 2026-08-17: 10Mentions · 2026-08-18: 47Mentions · 2026-08-19: 18Mentions · 2026-08-20: 10Mentions · 2026-08-21: 36Mentions · 2026-08-22: 11Mentions · 2026-08-23: 10Mentions · 2026-08-24: 12Mentions · 2026-08-25: 4Mentions · 2026-08-26: 5Mentions · 2026-08-28: 4Mentions · 2026-08-29: 2Mentions · 2026-08-30: 1Mentions · 2026-08-31: 1Mentions · 2026-09-14: 1Mentions · 2026-09-28: 1PoC Mentioned / Linked · 2026-08-18: 6PoC Mentioned / Linked · 2026-08-19: 4PoC Mentioned / Linked · 2026-08-20: 2PoC Mentioned / Linked · 2026-08-23: 3PoC Mentioned / Linked · 2026-08-24: 2PoC Mentioned / Linked · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-26: 2PoC Mentioned / Linked · 2026-08-28: 2PoC Mentioned / Linked · 2026-08-29: 1Exploit Tool / Code · 2026-08-18: 4Exploit Tool / Code · 2026-08-19: 2Exploit Tool / Code · 2026-08-20: 1Exploit Tool / Code · 2026-08-24: 1Exploit Tool / Code · 2026-08-28: 2Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-08-18: 2Active Exploitation · 2026-08-20: 5Active Exploitation · 2026-08-21: 28Active Exploitation · 2026-08-22: 9Active Exploitation · 2026-08-23: 8Active Exploitation · 2026-08-24: 8Active Exploitation · 2026-08-25: 3Active Exploitation · 2026-08-26: 4Active Exploitation · 2026-08-28: 1Active Exploitation · 2026-08-29: 2Active Exploitation · 2026-08-31: 1Active Exploitation · 2026-09-14: 1Patch / Workaround · 2026-08-17: 9Patch / Workaround · 2026-08-18: 30Patch / Workaround · 2026-08-19: 10Patch / Workaround · 2026-08-20: 5Patch / Workaround · 2026-08-21: 18Patch / Workaround · 2026-08-22: 8Patch / Workaround · 2026-08-23: 5Patch / Workaround · 2026-08-24: 5Patch / Workaround · 2026-08-25: 2Patch / Workaround · 2026-08-26: 3Patch / Workaround · 2026-08-28: 2Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-14: 1Technical Details · 2026-08-17: 8Technical Details · 2026-08-18: 37Technical Details · 2026-08-19: 12Technical Details · 2026-08-20: 8Technical Details · 2026-08-21: 16Technical Details · 2026-08-22: 7Technical Details · 2026-08-23: 5Technical Details · 2026-08-24: 5Technical Details · 2026-08-25: 2Technical Details · 2026-08-26: 4Technical Details · 2026-08-28: 2Technical Details · 2026-08-29: 2Technical Details · 2026-08-30: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-14: 108-1708-1808-1908-2008-2108-2208-2308-2408-2508-2608-2808-2908-3008-3109-1409-28
Signal classification6 categories
Active Exploitation
7141.3%
Patch
5330.8%
Disclosure
2414.0%
General
116.4%
PoC
116.4%
Exploit
21.2%
Referenced assets104 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-1710
Active Exploitation1Patch9
2026-08-1847
Active Exploitation2Disclosure10Exploit1General4Patch25PoC5
2026-08-1918
Disclosure6General2Patch7PoC3
2026-08-2010
Active Exploitation5Disclosure2General2Patch1
2026-08-2136
Active Exploitation28Disclosure3General2Patch3
2026-08-2211
Active Exploitation9Disclosure1Patch1
2026-08-2310
Active Exploitation7Disclosure1Patch1PoC1
2026-08-2412
Active Exploitation7Disclosure1General1Patch2PoC1
2026-08-254
Active Exploitation3Patch1
2026-08-265
Active Exploitation4Patch1
2026-08-284
Active Exploitation1Exploit1Patch1PoC1
2026-08-292
Active Exploitation2
2026-08-301
Patch1
2026-08-311
Active Exploitation1
2026-09-141
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Patch

    ‼️Critical GitLab vulnerability could let unauthenticated attackers delete public projects. CVE-2026-19478 affects self-managed CE and EE under certain conditions. Fixes are in 19.2.4, 19.1.6, 19.0.8, and 18.11.11. What admins need to know: https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html

    Post summary

    A critical GitLab vulnerability (CVE-2026-19478) permits unauthenticated deletion of public projects; patches are available in the listed versions.

    78443228573.3K
    2.4M followersView on X
  • H4x0r.DZ 🇰🇵@h4x0r_dz
    Patch

    Gitlab just patched a CRITICAL unauthenticated code injection https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/#cve-2026-19478---code-injection-issue-via-graphql-directive-impacts-gitlab-ceee https://t.co/SctpMQFhDt

    Post summary

    GitLab addressed CVE‑2026‑19478, a critical unauthenticated code‑injection flaw, with an official patch release.

    04002938617.0K
    83.6K followersView on X
  • Dhiyaneshwaran@DhiyaneshDK
    PoC

    🚨CVE-2026-19478 - GitLab CE/EE - GraphQL @ gl_introduced Arbitrary Method Invocation 🔍Nuclei Template - https://github.com/projectdiscovery/nuclei-templates/pull/16927/changes 🗒️Reference: https://github.com/davkharrr/CVE-2026-19478-PoC #hackwithautomation #bugbounty https://t.co/IB6gkWQki5

    Post summary

    The tweet announces CVE-2026-19478 in GitLab with a published PoC and detection template, but there is no evidence of active exploitation or a patch.

    13611841149.8K
    4.9K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🔻 Attackers are exploiting a GitLab flaw days after disclosure. CVE-2026-19478 lets unauthenticated attackers modify or delete public projects and rewrite their data under certain conditions. watchTowr says it saw in-the-wild exploitation against its honeypots. Running self-hosted GitLab? Patch now: https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html

    Post summary

    Attackers are actively exploiting GitLab CVE‑2026‑19478 in the wild, as evidenced by honeypot activity, and a vendor patch is available.

    34921683552.0K
    2.4M followersView on X
  • watchTowr@watchtowrcyber
    PoC

    🚨 GitLab CVE-2026-19478: a critical vulnerability lets unauthenticated attackers modify or delete public projects in one request. watchTowr reproduced it within minutes using Project Red, before any public exploit exists. Upgrade self-managed instances now, or restrict access to "/api/graphql" where possible.

    Post summary

    watchTowr demonstrated a proof of concept for GitLab CVE‑2026‑19478, enabling unauthenticated modification or deletion of public projects; administrators should upgrade or restrict /api/graphql access immediately.

    424091259.0K
    13.1K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Opening public the lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced ) , since it's already around. This is a 'safe env setup' https://github.com/dinosn/gitlab-cve-2026-19478-lab

    Post summary

    The post announces a public lab with a safe PoC for GitLab CVE‑2026‑19478 and CVE‑2026‑19650 and links to a GitHub repository, but it provides no exploit code, patches, technical specifications, or reports of active exploitation.

    215070366.6K
    161.9K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-19478 Vendor: GitLab Product: GitLab Description: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. Link: https://github.com/davkharrr/cve-2026-19478-poc #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑19478 is available, illustrating unauthenticated remote modification/deletion via GraphQL, while GitLab has released patches for the affected versions.

    113063175.4K
    3.6K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-19478 (CVSS 9.4): Critical unauthenticated GraphQL flaw in self-managed GitLab CE/EE allows remote attackers to modify or delete public projects and user data under certain conditions. Patched in 19.2.4, 19.1.6, 19.0.8, and 18.11.11. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJHaXRMYWIi%3D 🎯368.9K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="GitLab" 🔖Refer: https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The text announces a critical unauthenticated GraphQL vulnerability in GitLab, providing technical details and patch information, but no PoC, exploit code, or evidence of active exploitation.

    113035245.3K
    14.8K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Grave vulnerabilidad de GraphQL en GitLab podría permitir que atacantes no autenticados eliminen proyectos públicos GitLab lanzó actualizaciones urgentes para corregir una vulnerabilidad crítica (CVE-2026-19478) https://blog.elhacker.net/2026/08/grave-vulnerabilidad-de-graphql-en.html

    Post summary

    A critical GraphQL vulnerability (CVE‑2026‑19478) in GitLab that can let unauthenticated users delete public projects has been disclosed, and GitLab has issued urgent updates to patch it.

    11704774.8K
    142.1K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Reproduced GitLab CVE-2026-19478, on the few times that I'll held back the lab release as this is a direct destructive operation. Still 90 days embargo for PoC these days seem too long https://t.co/e25TN5pVh9

    Post summary

    The author reports reproducing GitLab CVE‑2026‑19478, holds back a lab release due to its destructive nature, and notes a 90‑day embargo on the PoC as too long.

    3304495.2K
    161.6K followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-19478: Improper Control of Generation of Code ('Code Injection') in GitLab Critical Vulnerability Alert! GitLab is affected by CVE-2026-19478. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-19478 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-19478" Search Dork: app="GitLab Exposure: 291.5k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJHaXRMYWI=&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260819 #Infosec #CyberSecurity #ZoomEye #DarkEye 🚀 ZoomEye continues to expand its AI ecosystem. Today we're introducing WebMCP support, enabling compatible AI agents to discover and invoke ZoomEye tools directly from the website. Explore our AI ecosystem: 1⃣ WebMCP 2⃣ MCP Server →(http://github.com/zoomeye-ai/mcp…) 3⃣ AI Skills →(http://ai.trusttools.cn/skills/zoomeye…) Building an AI-native cybersecurity platform. #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    A critical vulnerability alert for CVE-2026-19478 affecting GitLab, linking to DarkEye for analysis and providing ZoomEye search parameters for target identification.

    1702363.0K
    12.7K followersView on X
  • Abhishek@aacle_
    Exploit

    Studied CVE-2026-19478 today. one unauthenticated graphql query deletes a gitlab project. "future field" named destroy → validation strips it → fallback resolver calls public_send("destroy") on the object. that's it. that's the 9.4. lab + poc (EQSTLab): http://github.com/EQSTLab/CVE-2026-19478 — test in your own instance only, it's destructive.

    Post summary

    The author reports on CVE‑2026‑19478, revealing an unauthenticated GraphQL query that can delete GitLab projects and provides a GitHub‑hosted PoC demonstrating the exploit.

    31115113.5K
    49.5K followersView on X
  • CERT@certlv
    Active Exploitation

    ‼️Brīdinājums! GitLab CE/EE platformā konstatēta neautentificēta koda ievades (code injection) ievainojamība (CVSS 9.4), kas jau aktīvi tiek izmantota uzbrukumos kibertelpā. Tādēļ aicinām pēc iespējas ātrāk atjaunināt GitLab uz jaunāko versiju. Vairāk: https://cert.lv/lv/2026/08/kritiska-ievainojamiba-gitlab-platforma-cve-2026-19478 https://t.co/x3JLb78CaB

    Post summary

    The post warns that GitLab CE/EE suffers an unauthenticated code‑injection flaw (CVSS 9.4) that is already being exploited in the wild, urging users to upgrade immediately.

    01301443.1K
    5.7K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    CVSS 9.4が1本ある。国内大手2社のデータが漏れ、AIがAIを攻撃した。 開発環境もAIツールも、今から君が守るものだ。 ・Ray CVE-2025-62593(CVSS 9.4)、AI開発基盤にブラウザ経由RCE——KEV追加 ・日本交通に2.9TB窃取、ドライバー処分歴など機微情報が流出か ・M365 Copilot、隠しパラメータでガードレール突破——パスワード窃取 ・OpenAI自社AIがHugging Faceを攻撃、AI攻撃防止策10選を公開 ・ANAグループOCS、脆弱性悪用の不正アクセスで個人情報漏洩か ・GitLab CVE-2026-19478、未認証でプロジェクト削除可能 今日の6本に共通しているのは一つだ。 「使っているツールが入口になった」—— 君の組織で、これを誰がセキュリティの目で見ている?

    Post summary

    The post warns that multiple high‑severity CVEs, including CVE‑2025‑62593 and CVE‑2026‑19478, have already been actively exploited, causing data leaks and highlighting attacker use of AI tools as entry points, with no mitigation information disclosed.

    0102092.0K
    1.7K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 GitLab'da kritik güvenlik açığı: Yetkisiz saldırganlar public projeleri silebilir! GitLab, Community Edition (CE) ve Enterprise Edition (EE) sürümlerini etkileyen CVE-2026-19478 (CVSS: 9.4) adlı kritik güvenlik açığını kapattı. Açık, belirli koşullar altında kimlik doğrulaması gerektirmeden GraphQL üzerinden public projelerin ve kullanıcı verilerinin değiştirilmesine veya silinmesine yol açabiliyor. Etkilenen self-managed sürümler için düzeltmeler: • 18.11.11 • 19.0.8 • 19.1.6 • 19.2.4 http://GitLab.com ve GitLab Dedicated kullanıcılarının ise işlem yapmasına gerek bulunmuyor. GitLab, açığın nasıl sömürülebileceğine ilişkin teknik detayları henüz paylaşmadı. Şu an için public PoC veya aktif exploitation bilgisi de bulunmuyor. ⚠️ Self-managed GitLab kullananların sistemlerini vakit kaybetmeden güncellemesi öneriliyor.

    Post summary

    GitLab has released a critical patch for CVE‑2026‑19478, a GraphQL‑based vulnerability that allows unauthenticated deletion of public projects. Users are advised to apply the specified updates immediately.

    0212252.6K
    2.4K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html

    Post summary

    GitLab's CVE-2026-19478 was reported as being actively exploited within days of its disclosure, according to a The Hacker News article.

    0302005.5K
    161.9K followersView on X
  • Horizon3.ai@Horizon3ai
    Active Exploitation

    🚨 Critical GitLab vulnerability. Pre-auth. Actively exploited. Rapid Response test now available for CVE-2026-19478. https://t.co/KXvHYS2cVi

    Post summary

    The tweet highlights a critical pre‑authentication GitLab vulnerability (CVE‑2026‑19478) that is currently being actively exploited, and notes a Rapid Response test is available.

    1801031.0K
    3.0K followersView on X
  • Abhishek@aacle_
    PoC

    if you want to actually feel CVE-2026-19478 instead of just reading about it - punitdarji built a proper training lab for it. vulnerable gitlab 19.2.0 in docker, a staged walkthrough (recon → verify → exfil → destroy), even a simulated mode if your machine can't run full gitlab. and it's one of the few repos that ships detection rules + WAF snippet for defenders too. http://github.com/punitdarji/Gitlab-CVE-2026-19478 read the scripts before you run anything, keep it on localhost. that's the whole discipline.

    Post summary

    The GitHub repository offers a Docker-based training lab to experience CVE‑2026‑19478, including a staged exploitation walkthrough and defensive rules, but there is no indication of live exploitation in the wild.

    1106101.8K
    49.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    GitLab CVE-2026-19478 vulnerability lets unauthenticated attackers delete public projects. Exploited in the wild with public PoC. Patch now. #GitLab #CVE202619478 #Vulnerability #InfoSec #CyberSecurity #PatchNow http://securityonline.info/gitlab-cve-2026-19478/

    Post summary

    GitLab CVE-2026-19478 enables unauthenticated deletion of public projects and is being actively exploited in the wild with a public PoC; a patch is available.

    030105876
    13.0K followersView on X
  • Xakep.ru@XakepRU
    Active Exploitation

    Критический баг в GitLab уже взяли на вооружение хакеры Специалисты компании watchTowr сообщили, что хакеры начали использовать в реальных атаках критическую уязвимость CVE-2026-19478 в GitLab. https://xakep.ru/2026/08/26/gitlab-attacks/

    Post summary

    WatchTowr specialists report that attackers are already exploiting GitLab’s CVE‑2026‑19478 in real‑world attacks. No patches or detailed technical information are provided in the notice.

    021552.6K
    46.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more