Critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

Help Net Security
2 Sources
Reporting on this topic
Help Net SecurityThe Hacker News

Overview

GitLab has identified a critical vulnerability that could allow attackers to modify or delete public projects without needing to authenticate. This flaw, cataloged as CVE-2026-19478, affects several versions of both GitLab Community Edition and Enterprise Edition, specifically those released from version 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, and 19.2 to 19.2.3. Users running these versions are strongly urged to upgrade to the latest patched versions: 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The ability to alter or delete projects poses a significant risk, particularly for organizations relying on GitLab for public-facing repositories, as it could lead to data loss or compromise project integrity.

Key Takeaways

  • Affected Systems: GitLab Community Edition (CE) versions 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, 19.2 to 19.2.3; GitLab Enterprise Edition (EE) versions 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, 19.2 to 19.2.3.
  • Action Required: Users should upgrade to the patched versions: GitLab 19.
  • Timeline: Newly disclosed

Original Article Summary

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. “These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded … More → The post Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) appeared first on Help Net Security.

Impact

GitLab Community Edition (CE) versions 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, 19.2 to 19.2.3; GitLab Enterprise Edition (EE) versions 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, 19.2 to 19.2.3.

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

Users should upgrade to the patched versions: GitLab 19.2.4, 19.1.6, 19.0.8, or 18.11.11.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.

Multiple Sources: This threat is being reported by 2 different security sources, indicating significant concern within the cybersecurity community.