THREATOPS
THREAT OPSThreat News › CVE-2026-19478 | MeGitLab CE/EE GraphQL Directive Code Injection Vulnerability

CVE-2026-19478 | MeGitLab CE/EE GraphQL Directive Code Injection Vulnerability

medhorizon3Published 2026-08-20

<p>CVE-2026-19478 is a critical code injection vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). Under certain conditions, an unauthenticated remote attacker can exploit a GraphQL directive to modify or delete public projects and user data. The vulnerability has a CVSS 3.1 score of 9.4 and affects self-managed GitLab installations across multiple 18.x and 19.</p> <p><a hr

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-19478/

Same event, other sources