Vulnerability threat dossier

CVE-2026-19478

gitlabgitlab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

VTP deterministic threat22.7of 100 · CVSS excluded

VTP analyst assessment

GitLab GraphQL public-project modification or deletion

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence85%
Public exploitation · VTP factREPORTED

Assessment

Affected GitLab CE and EE versions can let an unauthenticated user modify or delete public projects and user data through a GraphQL directive. Public Nuclei tooling is available, and The Hacker News reported exploitation. Patch affected GitLab instances, especially where public projects are enabled.

Why it matters

  • Attackers could alter or delete public project content without authentication.
  • If you use affected GitLab versions, update to the remediated release and review GraphQL activity and unexpected changes to public projects.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The supplied exploitation reporting is press reporting and does not identify affected organizations.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Unauthenticated GraphQL requests targeting public projects.

AI baseline history (8)
  1. BASELINE ASSESSED
    GitLab GraphQL public-project modification or deletiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Reported GitLab data modification or deletion flawgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Unauthenticated GitLab GraphQL modification or deletiongpt-5.6-sol · high
  4. BASELINE ASSESSED
    GitLab flaw with reported active exploitationgpt-5.6-sol · high
  5. BASELINE ASSESSED
    GitLab integrity flaw with uncorroborated exploitation reportgpt-5.6-sol · high
  6. BASELINE ASSESSED
    Reported GitLab code-injection vulnerabilitygpt-5.6-sol · high
  7. BASELINE ASSESSED
    Preliminary reporting on a GitLab vulnerabilitygpt-5.6-sol · high
  8. BASELINE ASSESSED
    Reported GitLab GraphQL project-deletion vulnerabilitygpt-5.6-sol · high
Technical severityCRITICALCVSS 9.4 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.0693th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A proof of concept is reported; functional reliability is not established.

  2. 02

    EPSS is 0.06; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
CERT ADVISORYNew CERT advisory
03

Claim provenance

Evidence and source independence

10publications detected
10underlying evidence chains

1 primary sources · 0 dependent secondary reports · 8 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:8a15915ac64046879dfa4922f966118474d7af98ACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:7a1dd89dc497b98473a78c3214dfb42d235fbc26da8a5778e0b8f8b846f903daACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:1ebf2c13c8621b44503e49e9240067f1c7eedd88c3fa7c3e0b445254bb6c8d51ACTIVE
Evidence
04

Event history

Threat timeline

  1. 18:1724 Aug
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 14:3224 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 13:0824 Aug
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-19478.

  4. 07:0421 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  5. 00:0018 Aug
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-19478.

05

Original publications

Source record

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

CVE-2026-19478CVE-2026-85706CVE-2026-87719
Separate evidence group
Original

Exploit tooling coverage expanded for 51 CVEs

ProjectDiscovery nuclei-templates added or materially changed exploit-oriented artifacts covering 51 CVEs. This establishes public tooling availability; it does not establish exploitation in the wild or successful execution.

CVE-2015-7501CVE-2018-11714CVE-2018-14839CVE-2018-7282CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-44228CVE-2022-1281CVE-2023-25157CVE-2023-25826CVE-2023-27350CVE-2023-31059CVE-2023-3710CVE-2023-39143CVE-2024-33605CVE-2024-57726CVE-2025-0520CVE-2025-26399CVE-2026-0558CVE-2026-11387CVE-2026-12394CVE-2026-15826CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25895CVE-2026-26217CVE-2026-32255CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-4060CVE-2026-41042CVE-2026-45695CVE-2026-49069CVE-2026-5032CVE-2026-52806CVE-2026-53753CVE-2026-54917CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-61511CVE-2026-64849CVE-2026-6854CVE-2026-69084
Separate evidence group
Original

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

CVE-2021-27101CVE-2023-34362CVE-2026-12143CVE-2026-13242CVE-2026-14682CVE-2026-15580CVE-2026-15748CVE-2026-15826CVE-2026-18051CVE-2026-18963CVE-2026-19478CVE-2026-19505CVE-2026-19506CVE-2026-19507CVE-2026-19508CVE-2026-19509CVE-2026-20030CVE-2026-20231CVE-2026-20315CVE-2026-20317CVE-2026-20318CVE-2026-20319CVE-2026-20357CVE-2026-20358CVE-2026-20359CVE-2026-24301CVE-2026-25895CVE-2026-32475CVE-2026-40144CVE-2026-40145CVE-2026-41472CVE-2026-41473CVE-2026-47836CVE-2026-47841CVE-2026-55803CVE-2026-57580CVE-2026-59270CVE-2026-63093CVE-2026-63182CVE-2026-64849CVE-2026-65346CVE-2026-65770CVE-2026-65801CVE-2026-65816CVE-2026-65922CVE-2026-66794CVE-2026-6837CVE-2026-69106CVE-2026-69502CVE-2026-69555CVE-2026-69836CVE-2026-73570CVE-2026-74934CVE-2026-74935CVE-2026-74936CVE-2026-74949CVE-2026-75501CVE-2026-75874CVE-2026-76017CVE-2026-76034CVE-2026-76036CVE-2026-76310CVE-2026-76311CVE-2026-76312CVE-2026-76389CVE-2026-76395CVE-2026-76404
Separate evidence group
Original

Nuclei Templates v10.4.8 - Release Notes

New Templates Added: 112 | CVEs Added: 101 | First-time contributions: 22 🔥 Release Highlights 🔥 [CVE-2026-72898] Metabase - Unauthenticated SQL Injection (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-71362 ] Adobe Commerce/Magento - Customer Session Identity Switch (@0x_Akoko, @dinosn ) [critical] 🔥 [ CVE-2026-64849 ] MLflow Webhook SSRF - Unauth Full-Read via Redirect Bypass ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-64638] WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell) ( @flx | Nick Vidovic (greenhats)) [high] 🔥 [ CVE-2026-63077 ] JetBrains TeamCity < 2026.1.3, 2025.11.7 - RCE (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-59774] Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read ( @ashish-cybersec ) [critical] 🔥 [ CVE-2026-58644 ] Microsoft SharePoint Server - WS-Federation Deserialization RCE ( @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-57219] RabbitMQ Management - OAuth 2 Client Secret Disclosure ( @Aryu-RU ) [high] 🔥 [ CVE-2026-56270 ] Flowise <= 3.0.13 - Unauth OAuth Configuration Disclosure (@0x_Akoko, @pdteam ) [high] (vKEV) 🔥 [CVE-2026-53576] Kestra <= 1.3.20 - Remote Code Execution (@0x_Akoko, @pdteam , @Aryu-RU ) [critical] (vKEV) 🔥 [ CVE-2026-52806 ] Gogs <= 0.14.2 - Auth RCE via git rebase Argument Injection ( @dhiyaneshdk , @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-49049 ] JoomShaper Helix3 <=3.1.0 - Unauth Arbitrary JSON File Write ( @dhiyaneshdk , @pdteam ) [high] (vKEV) 🔥 [ CVE-2026-48939 ] Joomla iCagenda < 3.9.10 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-40217 ] LiteLLM < 1.25.0 - Remote Code Execution ( @ritikchaddha ) [high] (vKEV) 🔥 [ CVE-2026-34908 ] UniFi OS - Authentication Bypass via Path Traversal (..%2f) ( @Boreas37 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-20896 ] Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Auth Bypass ( @prithvee07 ) [critical] (vKEV) 🔥 [ CVE-2026-19478 ] GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method Invocation (@0x_Akoko, @dhiyaneshdk ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Corrected an unclosed string literal in the CVE-2026-0558 dsl matcher (PR #16950 ). Fixed a broken matcher in the newly added CVE-2026-3395 template (PR #16886 ). Fixed the username key structure in mysql-empty-password.yaml (PR #16939 ). Fixed indentation in kubernetes-metrics.yaml (PR #16934 ). Added the missing capture group to regex extractors in oracle-containers-panel, smtp-credentials-exposure and springboot-x-application-context (PR #16663 ). Corrected the max-request counter for CVE-2021-40822 (PR #16875 ). Corrected email and password variable names in CVE-2025-68613 (PR #16918 ). Renamed Wix-detect.yaml, cve-2026-44338 .yaml and CVE-2026-44381.yaml to match the naming convention (PRs #16731 , #16729 , #16730 ). Moved 22 invalid or rejected CVE templates to vulnerabilities (PR #16889 , Issue #16115 ). Removed CVE-2024-28752 .yaml (PR #16745 ). False Negatives CVE-2017-5521 , CVE-2017-7615 and CVE-2020-23575 — regexes were placed in word matchers, so these templates could never fire (PR #16666 ). nh-c2 — corrected a dsl matcher that could never match (PR #16739 ). CVE-2026-21858 — added a /rest/sentry.js fallback to detect n8n 1.65.0 through 1.111.x (PR #16888 ). CVE-2025-14847 — now detects vulnerable MongoDB 8.0.x via buildinfo read-size truncation (PR #16741 ). CVE-2025-32969 — removed an incorrect content_type matcher that suppressed matches (PR #16704 ). CVE-2023-37629 — closed the filename quote before the .php extension so the payload is well formed (PR #16709 ). False Positives CVE-2025-29927 — added negative matchers so WAF block pages returning HTTP 200 no longer match (PR #16870 , Issue #16782 ). wp-vr-view-xss and vrview-xss — no longer fire on hosts that escape the payload (PR #16912 ). wordpress-eol — tightened an over-broad version regex (PR #16752 ). CVE-2021-24139 — both conditions must now match rather than either (PR #16748 ). Marked prec

CVE-2015-7501CVE-2017-5521CVE-2017-7615CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-24139CVE-2021-40822CVE-2022-1281CVE-2022-29013CVE-2023-25826CVE-2023-37629CVE-2024-0200CVE-2024-13985CVE-2024-28752CVE-2024-37014CVE-2024-55890CVE-2024-56064CVE-2024-57726CVE-2025-0520CVE-2025-11953CVE-2025-13342CVE-2025-13528CVE-2025-14847CVE-2025-20282CVE-2025-26399CVE-2025-29927CVE-2025-32969CVE-2025-68613CVE-2025-71324CVE-2026-0558CVE-2026-0717CVE-2026-10768CVE-2026-1115CVE-2026-11387CVE-2026-12394CVE-2026-13001CVE-2026-13147CVE-2026-14483CVE-2026-14894CVE-2026-15733CVE-2026-15826CVE-2026-16268CVE-2026-17505CVE-2026-17532CVE-2026-17594CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25231CVE-2026-25895CVE-2026-2614CVE-2026-26217CVE-2026-27542CVE-2026-27796CVE-2026-3001CVE-2026-30965CVE-2026-32255CVE-2026-3395CVE-2026-34908CVE-2026-34976CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-40280CVE-2026-4060CVE-2026-41042CVE-2026-41432CVE-2026-42461CVE-2026-44338CVE-2026-44381CVE-2026-45332CVE-2026-45695CVE-2026-48030CVE-2026-48939CVE-2026-49049CVE-2026-49069CVE-2026-50160CVE-2026-5032CVE-2026-52806CVE-2026-53519CVE-2026-53576CVE-2026-53629CVE-2026-53753CVE-2026-53755CVE-2026-53976CVE-2026-54917CVE-2026-55087CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-58138CVE-2026-58644CVE-2026-59774CVE-2026-61511CVE-2026-61808CVE-2026-63030CVE-2026-63077CVE-2026-64638CVE-2026-64849CVE-2026-65442CVE-2026-65919CVE-2026-67208CVE-2026-6826CVE-2026-6854CVE-2026-69084CVE-2026-69251CVE-2026-71209CVE-2026-71362CVE-2026-72898CVE-2026-8236CVE-2026-8237CVE-2026-8857CVE-2026-9506
Separate evidence group
Original

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring

CVE-2026-19478
Separate evidence group
Original

Critical GitLab Flaw Exploited Shortly After Disclosure

CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data. The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek .

CVE-2026-19478
Separate evidence group
Original

Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.

CVE-2026-19478
Separate evidence group
Original

GitLab Patches Critical Code Injection Vulnerability

The security defect allows unauthenticated attackers to modify or delete user data and public projects. The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek .

CVE-2026-19478CVE-2026-19650
Separate evidence group
Original

Multiples vulnérabilités dans GitLab (18 août 2026)

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données et une injection de requêtes illégitimes par rebond (CSRF).

CVE-2026-19478CVE-2026-19650
Separate evidence group
Original

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on

CVE-2026-19478CVE-2026-19650
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score22.7vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction1.16 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.4 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CWE
CWE-94
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.