Ethical Hacking News
GitLab has issued an emergency patch to address a critical vulnerability that allows unauthenticated attackers to modify or delete public projects and user data. The vulnerability has a CVSS score of 9.4 and is currently under active exploitation, posing a significant risk to organizations that use GitLab.
GitLab has issued an emergency patch to address a critical GraphQL vulnerability (CVE-2026-19478) that allows unauthenticated attackers to modify or delete public projects and user data. The vulnerability has a CVSS score of 9.4, indicating a high level of severity, and is currently under active exploitation. Users of affected self-managed installations should upgrade to versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 to patch the issue. Organizations should urgently patch their internet-facing GitLab servers, restrict unauthenticated access to /api/graphql, and disable public repositories where possible. The vulnerability highlights the importance of regular patching and updates, particularly in cloud-based services like GitLab.
GitLab, a popular cloud-based project management and version control system, has issued an emergency patch to address a critical vulnerability (CVE-2026-19478) that allows unauthenticated attackers to modify or delete public projects and user data via a GraphQL directive. The vulnerability has a CVSS score of 9.4, indicating a high level of severity.
According to WatchTowr researchers, the vulnerability is currently under active exploitation, posing a significant risk to organizations that use GitLab. The researchers warn that the vulnerability could be exploited remotely, allowing an attacker to modify or delete public projects and user data without requiring any authentication credentials.
GitLab has emphasized that the vulnerability only affects self-managed installations, and users should upgrade to versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 to patch the issue. However, there is a gap in the available patches, which means that users running older releases (18.2 through 18.10) are left vulnerable until they can upgrade to a patched branch entirely.
To mitigate the risk, organizations should urgently patch their internet-facing GitLab servers, restrict unauthenticated access to /api/graphql, disable public repositories where possible, and check logs for requests containing @gl_introduced. These measures will help prevent unauthorized access to sensitive data and prevent the exploitation of the vulnerability.
The emergence of this vulnerability highlights the importance of regular patching and updates, particularly in the context of cloud-based services like GitLab. It also underscores the need for organizations to stay vigilant and proactive in protecting themselves against emerging threats.
In recent months, GitLab has faced several security concerns, including a screen sharing flaw that was exploited to deploy Monero miners on macOS systems and a Windows zero-day that was used in an Operation Dream Job by the North Korean Lazarus Group. These incidents demonstrate the importance of staying informed about the latest security threats and taking proactive measures to protect against them.
The incident also raises questions about the effectiveness of bug bounty programs, such as HackerOne, which reported the flaw to GitLab. While bug bounty programs can be an effective way to identify vulnerabilities, they are only as effective as the programs themselves and the skills of the researchers involved.
In conclusion, the active exploitation of the critical GraphQL flaw in GitLab highlights the importance of staying vigilant and proactive in protecting against emerging threats. Organizations should prioritize patching and updating their systems, restricting unauthenticated access to sensitive data, and staying informed about the latest security threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Active-Exploitation-of-Critical-GraphQL-Flaw-in-GitLab-Raises-Security-Concerns-ehn.shtml
https://securityaffairs.com/197622/uncategorized/gitlab-warns-of-active-exploitation-of-critical-graphql-flaw.html
https://cybernews.com/security/gitlab-critical-security-flaw-patch/
https://nvd.nist.gov/vuln/detail/CVE-2026-19478
https://www.cvedetails.com/cve/CVE-2026-19478/
Published: Fri Aug 21 06:09:19 2026 by llama3.2 3B Q4_K_M