THREATOPS
THREAT OPSThreat News › CVE-2026-19478: GitLab GraphQL Flaw Exploited

CVE-2026-19478: GitLab GraphQL Flaw Exploited

medsocradar_blogPublished 2026-08-24

<h1>CVE-2026-19478: GitLab GraphQL Flaw Exploited</h1> <p>GitLab has patched <strong>CVE-2026-19478</strong>, a critical code injection vulnerability affecting self-managed Community Edition (CE) and Enterprise Edition (EE) instances. Under certain conditions, an unauthenticated remote attacker could leverage a GraphQL directive to modify or delete public projects and user data. Because the flaw p

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://socradar.io/blog/cve-2026-19478-gitlab-graphql/