Exploited in the wild GitLab CE rce GitLab EE GitLab web-app
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
CVE Tools coverage
WatchTowr has detected active in-the-wild exploitation of CVE-2026-19478, a critical code injection vulnerability affecting GitLab CE and EE shortly after its public disclosure. With a CVSS score of 9.4, this flaw allows unauthenticated attackers to manipulate or delete public projects via the GraphQL interface without needing credentials. Affected versions include GitLab 18.2 prior to 18.11.11, 19.0 before 19.0.8, 19.1 prior to 19.1.6, and 19.2 before 19.2.4. Organizations should upgrade to the patched releases immediately or mitigate risk by restricting unauthenticated access to /api/graphql while reviewing web logs for suspicious @gl_introduced directives.