Critical GitLab Flaw Exploited Shortly After Disclosure
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.
Threat actors started exploiting a critical-severity GitLab vulnerability roughly two days after public disclosure, attack surface management company WatchTowr warns.
Tracked as CVE-2026-19478 (CVSS score of 9.4), the code injection defect was patched on August 17, when GitLab warned that it could be exploited remotely without authentication.
“GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive,” GitLab said.
Source: https://www.securityweek.com/critical-gitlab-flaw-exploited-shortly-after-disclosure/
Related breach coverage
- GitLab Patches Critical Code Injection Vulnerability2026-08-18
The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.
- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild2026-09-01
Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.
- GitLab Patches Critical Unauthenticated GraphQL Vulnerability2026-08-18
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user […]
- GitLab Vulnerability Exploited One Day After Disclosure2026-09-11
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.