GitLab CVE-2026-19478 Actively Exploited Days After Disclosure
A critical GitLab vulnerability is being exploited in the wild shortly after its public disclosure. Unauthenticated attackers can manipulate or destroy public project data.
TL;DR
- CVE-2026-19478 is a critical GitLab flaw with a CVSS score of 9.4.
- It enables unauthenticated attackers to modify or delete public projects.
- Exploitation began within days of the vulnerability being made public.
- Organizations using GitLab should patch immediately.
- The flaw highlights risks of rapid exploitation in widely used DevOps tools.
A severe security vulnerability in GitLab, identified as CVE-2026-19478, is now being actively exploited by threat actors. The flaw, which carries a high CVSS score of 9.4, allows unauthenticated attackers to modify or delete publicly accessible GitLab projects under specific conditions.
Security researchers from watchTowr first reported the issue, noting that attacks began appearing in the wild just days after the vulnerability was publicly disclosed. This rapid transition from patch release to active exploitation underscores the urgency for organizations to update their GitLab instances immediately.
Vulnerability Details
- CVE-2026-19478 is a code injection flaw affecting GitLab instances.
- It allows unauthenticated remote attackers to manipulate public project data.
- The vulnerability does not require login credentials to exploit.
- Its CVSS score of 9.4 indicates critical severity.
- Successful exploitation can lead to data modification or deletion.
Impact and Recommendations
- Publicly accessible GitLab projects are at risk of tampering.
- Organizations should apply available patches as soon as possible.
- Administrators should audit logs for signs of unauthorized access.
- Exposure window spans from initial disclosure to patch deployment.
- Delaying updates significantly increases compromise likelihood.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.