A critical vulnerability in GitLab allows, under certain circumstances, unauthenticated attackers to modify or delete public projects and user data. CVE-2026-19478 concerns the GraphQL function and has a CVSS score of 9.4. The GraphQL directive is at the center of the analysis.

The issue is located in a GraphQL directive, a mechanism that affects how GitLab processes queries and commands. The exploit is done over the network, does not require an account or user interaction, and can affect the availability and integrity of public content.
See also: PoC for RCE in GitLab installations
What we know about CVE-2026-19478
GitLab describes CVE-2026-19478 as an issue that could, under certain conditions, allow an unauthenticated user to modify or delete remote public projects and user data. The GraphQL directive is the technical point of the attack, but its exact name has not yet been made public.
The vulnerability is listed as CWE-94, a category that involves incorrect code generation control. GitLab's official assessment gives it a CVSS of 9.4 with low attack complexity, zero privilege requirements, and no interaction from the victim. As of writing, no public exploit has been reported.
The CVSS vector captures a risk that does not depend on stolen credentials or user action. The attack can be initiated remotely, while the potential impacts concern both the integrity of projects and the availability of data hosted within them.
GitLab has not yet released all the technical details. The company says that the issues will be made available in GitLab's reporting system after the scheduled disclosure period, which gives administrators time to implement fixes without having full public exploit code available.

According to GitLab's official security bulletin, CE and EE versions from the 18.2 series up to and before 18.11.11 are affected, as well as 19.0 series before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The NVD entry for CVE-2026-19478 confirms the same version range.
Who needs to act immediately?
GitLab has released the fixes in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4. Choosing the right version depends on the release series your organization is using, not just the latest available version number. Administrators of CE and EE installations should check their release series and upgrade accordingly as soon as possible. These releases do not include new database moves and, in multi-node installations, are not expected to require downtime.
The guidance is primarily for self-managed installations. GitLab.com and GitLab Dedicated were already running a patched version, so customers of these services do not need to take any action for this CVE. However, verifying settings and permissions remains a good practice.
Before making the change, teams can check for public projects containing sensitive data, confirm which accounts have administrative rights, and maintain a record of the current state. This makes it easier to detect any unexpected changes after the upgrade.
See also: GitLab fixes vulnerabilities in CE and EE

GraphQL directive and practical protection measures
The SecNews technical team recommends that administrators record the current version, check if the system is in one of the affected series, and schedule the upgrade based on the organization's change processes. Maintaining backups and testing restores are essential before any critical change.
Until the patch is fully deployed, security teams can limit the exposure of management interfaces, monitor for unusual changes to public projects, and check logs for unexpected GraphQL commands. No official workaround has been released to replace the upgrade.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Exposed key opens repositories
CVE-2026-19478 demonstrates why GitLab installations need to regularly check versions and quickly apply critical updates. The lack of a login requirement increases the risk for exposed systems, while timely migration to a patched version limits the scope for malicious exploitation.
