What is CVE-2026-19478?
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Timeline
- 2026-08-17Published to the U.S. National Vulnerability Database (NVD)
- 2026-09-02NVD record last updated
Affected product
Gitlab
Remediation Steps
- Apply the latest GitLab security patch addressing CVE-2026-19478 immediately
- Review audit logs for evidence of unauthorized project modifications or deletions
- Restrict public project visibility to trusted users pending patch deployment
- Monitor GitLab instances for suspicious code injection activity
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of August 2026 (August 24 – 30)
- Vulnerability Priority Report – Week 3 of August 2026 (August 17 – 23)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.