GitLab CVE-2026-19478: Critical GraphQL Flaw Can Modify or Delete Public Data

GitLab CVE-2026-19478 is a critical GraphQL code-injection vulnerability affecting self-managed GitLab Community Edition and Enterprise Edition. GitLab says that, under certain conditions, an unauthenticated remote user could use a GraphQL directive to modify or delete public projects and user data.

The vulnerability carries a CVSS 3.1 score of 9.4. GitLab patched the issue on August 17, 2026 in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4. GitLab.com and GitLab Dedicated were already running patched versions when the advisory was published.

For self-managed administrators, the practical lesson is straightforward: this is not a confidentiality-only bug. Its strongest CVSS impacts are integrity and availability, because successful exploitation can change or remove data.

What Is GitLab CVE-2026-19478?

GitLab describes CVE-2026-19478 as an improper control of code generation issue, mapped to CWE-94. The vulnerable behavior exists in GitLab’s GraphQL handling and can be reached remotely without authentication or user interaction under the affected conditions.

GitLab’s CVSS vector is:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

That vector means the attack is network-reachable, low-complexity, requires no privileges and no user interaction. GitLab rates confidentiality impact as low, while integrity and availability impacts are high.

Which GitLab Versions Are Affected?

Affected branchVulnerable versionsPatched version
18.x18.2 through versions before 18.11.1118.11.11 or later
19.019.0 through versions before 19.0.819.0.8 or later
19.119.1 through versions before 19.1.619.1.6 or later
19.219.2 through versions before 19.2.419.2.4 or later

GitLab strongly recommends that affected self-managed installations upgrade to the latest patch release available for their supported version.

Why This Vulnerability Matters to DevOps Teams

GitLab is often more than a source-code host. In many environments it sits directly inside the software delivery path, alongside CI/CD pipelines, deployment automation, container registries, issue tracking and developer identity.

CVE-2026-19478 specifically concerns modification or deletion of public projects and user data. Teams should avoid overstating that into claims of automatic full server takeover or unrestricted access to every private repository; GitLab’s advisory does not make those claims.

Even with that narrower scope, unauthorized modification or deletion can still affect repository integrity, availability and trust in public development assets. For organizations that distribute software or infrastructure code publicly, unauthorized changes can also create downstream review and supply-chain concerns.

What GitLab Administrators Should Do

  • Check the installed version: confirm whether your self-managed instance falls into one of the affected ranges.
  • Upgrade to a patched release: move to 18.11.11, 19.0.8, 19.1.6, 19.2.4, or a newer supported release that contains the fix.
  • Review recent project changes: look for unexpected modification or deletion activity affecting public projects or user data.
  • Verify backups and recovery: because availability impact is rated high, make sure repository and application recovery procedures are usable.
  • Keep GitLab patching in the normal CI/CD security process: critical GitLab patches should be treated as application infrastructure maintenance, not as an occasional manual task.

GitLab said the August 17 patch versions introduced no new migrations and that multi-node deployments should not require downtime, although default Omnibus package behavior can still stop, reconfigure and start services during updates. Administrators should follow GitLab’s normal upgrade procedure for their deployment type.

CVE-2026-19650 Was Fixed in the Same Release

The same GitLab patch release also fixed CVE-2026-19650, a high-severity GraphQL issue with a CVSS score of 7.1.

GitLab says improper validation in the GraphQL multiplex query handler could, under certain conditions, allow mutations to be executed through GET requests. Its CVSS vector includes UI:R, meaning successful exploitation requires user interaction.

Both issues reinforce the importance of keeping self-managed GitLab instances on supported patch levels rather than waiting for the next feature upgrade.

How This Differs From CVE-2026-85706

GitLab later disclosed another critical issue, CVE-2026-85706, a CVSS 10.0 path-traversal vulnerability that can allow unauthenticated arbitrary file reads under affected conditions and was later added to CISA’s Known Exploited Vulnerabilities catalog.

The two vulnerabilities have different security impacts: CVE-2026-19478 focuses on unauthorized modification or deletion of public project and user data, while CVE-2026-85706 concerns file disclosure. Both, however, demonstrate why self-managed GitLab patching should be treated as part of core DevOps security operations.

Avoid These Two Common Response Mistakes

  • Do not assume CVSS 9.4 means every GitLab instance is already compromised. Severity describes technical impact and exploit conditions; it does not establish compromise on a particular server.
  • Do not wait for public exploitation evidence before patching. GitLab already provides fixed versions and explicitly recommends immediate upgrades for affected self-managed installations.

The same principle applies to infrastructure changes outside GitLab: changes should be reviewed, controlled and brought back into managed workflows. See our practical guide to detecting and fixing Terraform state drift.

Bottom Line

GitLab CVE-2026-19478 is a critical, remotely reachable GraphQL code-injection issue that GitLab says can allow an unauthenticated attacker to modify or delete public projects and user data under certain conditions.

Self-managed installations in the affected ranges should be upgraded to a fixed or newer supported release. GitLab.com and GitLab Dedicated customers were already patched when the advisory was issued.

Official Sources

Frequently Asked Questions

Does CVE-2026-19478 affect GitLab.com?

GitLab says GitLab.com and GitLab Dedicated were already running patched versions when the advisory was published. The upgrade action applies to affected self-managed installations.

What can CVE-2026-19478 allow an attacker to do?

GitLab says that, under certain conditions, an unauthenticated remote user could modify or delete public projects and user data through a GraphQL directive.

Which versions fix CVE-2026-19478?

GitLab fixed the issue in 18.11.11, 19.0.8, 19.1.6 and 19.2.4. Administrators should use one of those versions or a newer supported release containing the fix.

About the author

Kiran Sonawane

Kiran Sonawane is a DevOps engineer working with AWS, Azure, Google Cloud, Terraform and Kubernetes. His experience includes infrastructure automation, CI/CD pipelines, cloud security and deploying AI applications. At TechUpdate24, he writes about cloud engineering, DevOps, security and AI tooling.