PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19478 GitLab CVE debrief

GitLab CE/EE versions 18.2 through 19.2 are vulnerable to an issue that could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. The CVSS score for this vulnerability is 9.4, indicating a critical severity. This issue affects all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Administrators and users should be aware of this vulnerability and take steps to patch or mitigate it.

Vendor
GitLab
Product
Unknown
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-02
Advisory published
2026-08-17
Advisory updated
2026-09-02

Who should care

Administrators and users of GitLab CE/EE versions 18.2 through 19.2 should be aware of this vulnerability and take steps to patch or mitigate it. This includes reviewing and applying patches for affected versions, inventorying and updating affected GitLab installations, and monitoring for unusual GraphQL activity. Security teams and operators managing GitLab deployments should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Additionally, compensating controls for exposed systems should be reviewed while remediation is scheduled and verified, and relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retesting of remediated assets, and documentation of evidence should also be tracked and verified before closing the item. Users with affected deployments should confirm whether they exist in managed environments and assign an owner for follow-up. This vulnerability has a high impact on platform, vulnerability-management, and security-team operations due to its critical severity and potential for remote exploitation. Therefore, it is crucial for operators and security teams to prioritize patching and implement compensating controls where necessary to minimize potential damage. The vulnerability's impact on security teams includes the need for immediate review of affected systems, prioritization of patching, and verification of compensating controls. For operators, it involves confirming affected deployments, assigning owners for follow-up, and ensuring that patches are applied in accordance with change control processes. Overall, the vulnerability requires a coordinated effort from both security teams and operators to mitigate its effects effectively. The issue's technical impact involves the potential for remote modification or deletion of public projects and user data, which can lead to significant operational disruptions if exploited. Consequently, a thorough review of the vulnerability's technical details and affected systems is essential to ensure a

Technical summary

The vulnerability in GitLab CE/EE versions 18.2 through 19.2 allows an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. This issue has a CVSS score of 9.4, indicating a critical severity. The affected versions are 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. To address this vulnerability, administrators should prioritize patching to prevent potential remote modification or deletion of public projects and user data.

Defensive priority

Organizations using GitLab CE/EE versions 18.2 through 19.2 should prioritize patching to prevent potential remote modification or deletion of public projects and user data.

Recommended defensive actions

  • Apply patches for GitLab CE/EE versions 18.2 through 19.2
  • Inventory and update affected GitLab installations
  • Monitor for unusual GraphQL activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record indicates that GitLab has remediated an issue affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The issue could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19478 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19478

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19478 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19478

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.