THREAT OPS › Threat News › CVE-2026-19478 | MeGitLab CE/EE GraphQL Directive Code Injection Vulnerability
CVE-2026-19478 | MeGitLab CE/EE GraphQL Directive Code Injection Vulnerability
<p>CVE-2026-19478 is a critical code injection vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). Under certain conditions, an unauthenticated remote attacker can exploit a GraphQL directive to modify or delete public projects and user data. The vulnerability has a CVSS 3.1 score of 9.4 and affects self-managed GitLab installations across multiple 18.x and 19.</p> <p><a hr
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-19478cve
Original source: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-19478/
Same event, other sources
- GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosurethehackernews · 2026-08-21