CVE-2026-19478
GitLab Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Under certain conditions, the flaw allows an unauthenticated remote attacker to modify or delete public projects and user data via a malicious GraphQL directive. It was disclosed and patched on August 17, 2026, with a CVSS v3.1 base score of 9.4 (Critical) (GitHub Advisory).

Détails techniques

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), arising from insufficient validation of GraphQL directive inputs in GitLab's API layer (GitHub Advisory). An unauthenticated attacker can craft a malicious GraphQL directive and submit it over the network with no privileges or user interaction required, exploiting the flaw under certain unspecified conditions to manipulate or destroy public project data. The vulnerability was originally reported via HackerOne (report #3926431) and tracked internally at GitLab work item #611377 (GitHub Advisory). No public proof-of-concept exploit code has been confirmed at the time of disclosure.

Impact

Successful exploitation allows an unauthenticated attacker to remotely modify or delete public GitLab projects and associated user data, resulting in high integrity and availability impact. There is also a low confidentiality impact, potentially exposing limited project metadata or user information. The attack is automatable and network-accessible, meaning large-scale or targeted destruction of public repositories is feasible without any credentials (GitHub Advisory, The Hacker News).

Exploitabilité

As of disclosure on August 17, 2026, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is reported at 0.0, reflecting low current exploitation probability, though the vulnerability is marked as automatable by NVD SSVC analysis. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A GitHub repository (HORKimhab/CVE-2026-19650-CVE-2026-19478) referencing this CVE appeared shortly after disclosure, but no weaponized exploit has been confirmed.

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing GitLab CE/EE instances running versions 18.2–18.11.10, 19.0.0–19.0.7, 19.1.0–19.1.5, or 19.2.0–19.2.3 using tools such as Shodan, Censys, or FOFA by querying for GitLab login pages or version banners.
  2. Identify target public projects: Browse the GitLab instance without authentication to enumerate publicly accessible projects and their identifiers via the web UI or GraphQL API (/api/graphql).
  3. Craft malicious GraphQL directive: Construct a GraphQL mutation or query containing a specially crafted directive that exploits the code injection flaw in GitLab's GraphQL processing layer, targeting project modification or deletion operations.
  4. Submit unauthenticated request: Send the crafted GraphQL request to the /api/graphql endpoint without any authentication headers, leveraging the missing authorization check under the specific triggering conditions.
  5. Achieve impact: If the conditions are met, the server processes the injected directive and executes unauthorized modification or deletion of the targeted public project data or user records (GitHub Advisory, The Hacker News).

Indicateurs de compromis

  • Network: Unusual unauthenticated POST requests to /api/graphql containing GraphQL directives with unexpected or malformed syntax; high-volume GraphQL mutation requests from a single IP targeting project deletion or modification operations.
  • Logs: GitLab application logs (production.log) showing GraphQL mutation errors or unexpected project deletion/modification events attributed to unauthenticated sessions; Rails exception logs referencing GraphQL directive processing.
  • Application Events: Sudden disappearance or modification of public projects with no corresponding authenticated user activity in audit logs; audit log entries showing project deletions with no associated user identity.
  • Process: Unexpected GitLab Sidekiq background jobs triggered for bulk project destruction without a corresponding admin or owner action.

Atténuation et solutions de contournement

GitLab has released patched versions addressing this vulnerability: 18.11.11, 19.0.8, 19.1.6, and 19.2.4. All GitLab CE/EE administrators running affected versions (18.2–18.11.10, 19.0.x, 19.1.x, 19.2.x) should upgrade immediately (GitHub Advisory, GitLab Patch Release). If immediate patching is not possible, restrict network access to GitLab instances (e.g., via firewall rules or VPN), limit public project exposure, and monitor GraphQL API traffic for anomalous unauthenticated mutation requests.

Réactions de la communauté

The vulnerability received significant coverage from security media outlets including The Hacker News, which published an article titled "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects" (The Hacker News). Security community members on Mastodon (infosec.exchange) and Reddit's r/SecOpsDaily discussed the severity and urged rapid patching. The FOFA threat intelligence bot also flagged the CVE on social media, indicating active interest from the reconnaissance community. Multiple security news aggregators (SecurityOnline, CyberPress, IT Security News) republished coverage, reflecting broad industry awareness of the critical rating.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté GitLab Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-19478CRITICAL9.4
  • GitLab logoGitLab
  • gitlab-rails-19.1
NonOuiAug 17, 2026
CVE-2026-10053HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiAug 23, 2026
CVE-2026-19650HIGH7.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NonOuiAug 17, 2026
CVE-2026-6821MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NonOuiAug 12, 2026
CVE-2026-4879MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NonOuiAug 12, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités