CVE Tools
Back to feed
Exploited in the wild GitLab CE rce GitLab EE GitLab zero-day

Критический баг в GitLab уже взяли на вооружение хакеры

Хакер (xakep.ru)·By Мария Нефёдова··1 min read
CVE Tools coverage

watchTowr has confirmed active in-the-wild exploitation of CVE-2026-19478, a critical vulnerability affecting GitLab Community Edition and Enterprise Edition. This unauthenticated GraphQL flaw, rated 9.4 on the CVSS scale, enables attackers to remotely modify or delete public projects and alter repository data without requiring credentials or user interaction.

Versions ranging from 18.2 through 18.11.11, as well as those from 19.0 up to 19.2.4, remain vulnerable until patched with the latest releases (19.2.4, 19.1.6, 19.0.8, or 18.11.11). Security experts warn that AI-driven tools have drastically reduced the time between disclosure and attack, urging administrators to immediately apply updates or restrict unauthenticated access to /api/graphql while checking logs for @gl_introduced strings.