Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
Brief
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18. 2 before 18.
- 11, 19. 0 before 19.
- 8, 19. 1 before 19.
- 6, and 19. 2 before 19.
- 4. The fixes are available in GitLab 19.
- 4, 19.
- 6, 19.
- 8, and 18.
- 11. “These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded … More →
The post Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) appeared first on Help Net Security .
