Executive Summary
A critical vulnerability, CVE-2026-19478, has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE), enabling unauthenticated attackers to remotely delete or modify public projects and user data through a malicious GraphQL directive. This flaw, rated CVSS 9.4 (Critical), affects self-managed GitLab installations and poses a severe risk of data loss and supply chain compromise. As of this report, there is no evidence of exploitation in the wild, no public proof-of-concept code, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Immediate patching is strongly advised.
Technical Information
CVE-2026-19478 is a code injection vulnerability in the GraphQL API of GitLab CE and EE. The flaw allows remote, unauthenticated attackers to send specially crafted GraphQL directives to vulnerable instances, resulting in the deletion or modification of public projects and associated user data. The attack requires no authentication or user interaction, making exploitation trivial for any actor with network access to the target instance.
The vulnerability is present in all self-managed GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab.com and GitLab Dedicated are not affected, as they have already been patched.
The vulnerability was responsibly disclosed by security researcher hiimguardian via the HackerOne bug bounty program. GitLab released patches on August 17, 2026, and will publish full technical details 90 days post-patch (mid-November 2026). The patch does not require downtime for multi-node deployments and introduces no new database migrations.
From a technical perspective, the flaw is rooted in improper authorization checks within the GraphQL API, allowing unauthenticated requests to invoke destructive operations on public projects. The attack vector is network-based, and the impact includes high integrity and availability loss, with potential confidentiality exposure if project data is exfiltrated prior to deletion.
The vulnerability maps to several MITRE ATT&CK techniques: Impact (TA0040), Data Destruction (T1485), Account Manipulation (T1098) if user data is altered, and Exploitation of Public-Facing Application (T1190) for initial access.
Exploitation in the Wild
As of August 18, 2026, there are no confirmed reports of exploitation in the wild for CVE-2026-19478. No public proof-of-concept code or exploit scripts have been observed on security forums, code repositories, or threat intelligence feeds. The vulnerability is not listed in the CISA KEV catalog, and thus there is no CISA-confirmed active exploitation. However, the critical nature and ease of exploitation (no authentication or user interaction required) make this a high-priority issue for all organizations running self-managed GitLab instances.
APT Groups using this vulnerability
No advanced persistent threat (APT) groups or other threat actors have been publicly linked to exploitation of CVE-2026-19478 as of this report. There is no evidence of sector or country-specific targeting, and no attribution has been made in open-source intelligence or vendor advisories. Organizations should remain vigilant, as the lack of current exploitation does not preclude rapid adoption by threat actors once technical details or exploit code become available.
Affected Product Versions
The following GitLab product versions are affected by CVE-2026-19478: all versions of GitLab CE/EE from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Only self-managed deployments are impacted; GitLab.com and GitLab Dedicated have already been patched and are not vulnerable.
Workaround and Mitigation
The only effective mitigation is to upgrade all self-managed GitLab CE/EE installations to the latest patched versions: 18.11.11, 19.0.8, 19.1.6, or 19.2.4. These patches were released on August 17, 2026, and address the underlying authorization flaw in the GraphQL API. No downtime is required for multi-node deployments, and no new database migrations are introduced. Organizations should also monitor for any suspicious deletion or modification of public projects and remain alert for the release of technical details or proof-of-concept code after the 90-day embargo period.
Indicators of Compromise
Indicators of compromise are point-in-time and should be validated before enforcement. At the time of writing, no public indicators of compromise specific to exploitation of CVE-2026-19478 were available.
References
The Hacker News: Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects, GitLab Official Patch Release Notes, LinkedIn: A security commentator on GitLab GraphQL Flaw, Facebook: The Hacker News Post, Instagram: The Hacker News Post
Rescana is here for you
Rescana provides a comprehensive third-party risk management (TPRM) platform, empowering organizations to continuously monitor, assess, and mitigate cyber risks across their supply chain and vendor ecosystem. Our platform delivers actionable intelligence and automated workflows to help you stay ahead of emerging threats. For any questions or further assistance, our team is happy to help at info@rescana.com.


