HackMyIP
← Back to News
2026-08-21 The Hacker News

Critical GitLab CVE-2026-19478 Exploited Within Days — Patch Now

VulnerabilityZero-DayAI Threats

A critical code injection vulnerability in GitLab, tracked as CVE-2026-19478 with a CVSS score of 9.4, has come under active in-the-wild exploitation just days after public disclosure, according to preemptive exposure management firm watchTowr. The flaw allows unauthenticated attackers to modify or delete publicly accessible GitLab projects and rewrite their data without credentials, user interaction, or specialized configuration. Affected versions include GitLab Community Edition (CE) and Enterprise Edition (EE) 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. Patched releases are now available in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

According to GitLab, the vulnerability can be exploited via a GraphQL directive, and watchTowr principal security researcher Jake Knott told The Hacker News that his team reproduced the flaw within minutes of disclosure and observed exploitation attempts against its honeypot network. "This is the new reality of vulnerability reproduction and exploitation, where AI-enabled attackers are able to compress the time from disclosure to exploitation, and 'waiting until the next patch cycle' is often too late," Knott warned. watchTowr noted that the impact extends well beyond tampering with public projects: an attacker can delete entire repositories, forge merge records to fabricate a code fix that never landed, and ban project maintainers outright — actions that could devastate software supply chain integrity for organizations running self-hosted GitLab instances.

The rapid weaponization of this flaw underscores how AI is dramatically compressing the window between disclosure and mass exploitation, leaving defenders with razor-thin response timelines. Security teams running internet-facing self-hosted GitLab deployments should prioritize immediate upgrades, and those unable to patch right away are advised to restrict unauthenticated access to the "/api/graphql" endpoint or remove public repository access entirely as short-term mitigations. Administrators should also hunt through web logs for requests containing the string "@gl_introduced" to identify probes or active exploitation attempts. Organizations can begin hardening their broader attack surface by running a privacy checkup and verifying their public-facing infrastructure with a port scanner to ensure no exposed GitLab instances are overlooked. Teams can additionally validate TLS configurations on their GitLab frontends using the SSL/TLS checker to reduce the risk of man-in-the-middle attacks chaining with this vulnerability.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →