GitLab has released security updates for a critical vulnerability in its Community Edition and Enterprise Edition software that could allow unauthenticated attackers to remotely modify or delete public projects and user data under certain conditions.
Tracked as CVE-2026-19478, the vulnerability has been rated Critical by GitLab and assigned a CVSS score of 9.4. The company released the security update on August 17, 2026, outside its normal twice-monthly patch schedule.
The emergency release came just five days after GitLab’s previous routine security update, which did not contain any critical-rated vulnerabilities.
The issue affects self-managed GitLab installations. GitLab.com and GitLab Dedicated customers do not need to take action because those services are already running patched versions, according to the company.
GitLab has fixed the vulnerability in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. Affected versions include releases from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6 and 19.2 before 19.2.4.
GitLab said the vulnerability could allow an unauthenticated user to remotely modify or delete public projects and user data through a GraphQL directive. The company has not disclosed the specific directive involved or explained the conditions required to successfully exploit the flaw.
The published CVSS information indicates that the vulnerability can be exploited remotely over a network without authentication and does not require any action from a victim.
GitLab has not reported exploitation of CVE-2026-19478, and no public proof-of-concept exploit code for the vulnerability had appeared on GitHub as of August 18, 2026.
The same security release also addresses a separate high-severity vulnerability tracked as CVE-2026-19650. The flaw has a CVSS score of 7.1 and involves a cross-site request forgery vulnerability in GitLab’s GraphQL multiplex query handler.
Unlike the critical vulnerability, exploitation of CVE-2026-19650 requires user interaction. GitLab said the issue could under certain conditions allow an unauthenticated attacker to execute mutations through GET requests because of improper request validation when handling GraphQL multiplex queries.
The company said the security update does not introduce any new database migrations and is not expected to require downtime for multi-node deployments.
The latest disclosure follows a July 2026 report involving a separate GitLab vulnerability affecting self-managed servers, for which researchers published working exploit code.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
GitLab has said it publishes technical details about vulnerabilities on its public issue tracker 90 days after the release containing the fix. The company’s June 10, 2026 patch release changed that disclosure period from 30 days to 90 days, meaning more detailed technical information about the two newly patched vulnerabilities is expected around mid-November 2026.
Critical GitLab Flaw Could Let Attackers Delete Public Projects





