Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks
Brief
GitLab administrators are being urged to patch immediately after security researchers observed attempts to exploit CVE-2026-19478 , a critical unauthenticated code injection vulnerability affecting self-managed GitLab Community Edition and Enterprise Edition instances.
The flaw, rated 9. 4 out of 10, can allow remote attackers to modify or delete public projects and associated user data through GitLab’s GraphQL interface. GitLab issued an out-of-band update on August 17, 2026, outside its regular security release schedule.
The issue stems from improper handling of a GraphQL directive, which can be abused under specific conditions without requiring an account, authentication, or user interaction. This makes internet-facing GitLab deployments especially exposed.
