CVE-2026-19478
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-19478 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
GitLab Inc. has fixed vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerabilities are present in GitLab's GraphQL implementation. A first vulnerability made it possible for unauthenticated users to perform unauthorized modifications or deletions on public projects and user data through a GraphQL directive. A second vulnerability allowed unauthenticated users to perform mutations through GET requests due to improper validation of GraphQL multiplex queries, where mutation operations were not correctly restricted. This allows unauthorized parties to make unauthorized changes to the state of the server.
CSIRTS triage
- What
- Two GraphQL vulnerabilities allow unauthenticated users to perform unauthorized modifications and deletions on public projects via an improper directive and to execute mutations through GET requests due to insufficient multiplex query validation.
- Who is affected
- All GitLab CE and EE deployments with public projects and GraphQL enabled are affected.
- Urgency
- High urgency; unauthenticated attackers can modify or delete data without authentication.
- Action
- Update GitLab to the patched version that fixes the GraphQL directive and multiplex query validation issues.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-19478
Get an email if CVE-2026-19478 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-19478 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (4)
- unknownNCSC-2026-0303 [1.00] [M/H] Vulnerabilities Fixed in GitLab by GitLab Inc.ncsc-nl · 2026-08-18
- criticalCVE-2026-19478: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.1…nvd · 2026-08-17
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab · 2026-08-17
- criticalGitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11gitlab · 2026-08-17
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-19478)