CVE Tools
Back to feed
Exploited in the wild GitLab CE rce GitLab EE GitLab web-app

Critical GitLab Flaw Exploited Shortly After Disclosure

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

WatchTowr has confirmed that threat actors began actively exploiting CVE-2026-19478, a critical code injection flaw in GitLab Community Edition (CE) and Enterprise Edition (EE), just two days after its public disclosure. The vulnerability allows unauthenticated attackers to remotely manipulate public projects, including deleting repositories and forging merge records, without requiring any prior credentials. Users are urged to update to fixed versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, or mitigate risk by restricting access to the /api/graphql endpoint.