GitLab has released an emergency security update to address a critical vulnerability affecting both its Community Edition and Enterprise Edition platforms that could allow an unauthenticated attacker to remotely modify or delete public projects and user data under certain conditions. The flaw, tracked as CVE 2026 19478, has been assigned a Critical severity rating with a CVSS score of 9.4. The company issued the patch on August 17, 2026, outside its normal release schedule, just five days after its regular update cycle that contained no critical security issues. GitLab stated that only organizations running self managed installations are required to take action, while GitLab.com and GitLab Dedicated customers are already protected because those services are operating on patched versions.
The security fixes are available in GitLab versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. According to the company, the affected releases include all versions from 18.2 before 18.11.11, version 19.0 before 19.0.8, version 19.1 before 19.1.6, and version 19.2 before 19.2.4. GitLab also confirmed that versions between 18.2 and 18.10 remain within the affected range and are not receiving fixes. The company explained that the vulnerability could allow an unauthenticated user to remotely modify or delete public projects and user data through a GraphQL directive under specific conditions. However, GitLab has not disclosed the exact GraphQL directive involved or the technical requirements necessary for successful exploitation. The published CVSS vector indicates that the flaw can be exploited remotely over a network without requiring attacker credentials or any interaction from a victim, making it particularly significant for organizations operating exposed self managed GitLab instances.
Alongside the critical issue, GitLab also addressed a second vulnerability identified as CVE 2026 19650, which has been rated High with a CVSS score of 7.1. This flaw involves a cross site request forgery weakness in the GraphQL multiplex query handler. Unlike the critical vulnerability, successful exploitation requires user interaction. According to GitLab, the issue could allow an unauthenticated attacker to execute GraphQL mutations through GET requests because of improper request validation in the GraphQL multiplex query handling process. The company noted that the latest security update introduces no new database migrations and is not expected to require downtime for multi node deployments, allowing organizations to apply the patches with minimal operational disruption. GitLab also stated that GitLab.com and GitLab Dedicated customers do not need to perform any action because those hosted environments have already been updated with the security fixes.
The disclosure follows increased security attention surrounding GitLab after researchers published working proof of concept exploit code in July 2026 for a separate remote code execution vulnerability affecting self managed GitLab servers. In the latest advisory, GitLab said it has not identified any evidence that either of the newly disclosed vulnerabilities has been actively exploited, and as of August 18, 2026, no public exploit code had appeared on GitHub for either issue. The company also did not provide additional technical details regarding the vulnerabilities, stating that complete issue reports will be published on its public issue tracker 90 days after the release of the patches. GitLab noted that its previous policy, reflected in the June 10, 2026 patch release, provided a 30 day disclosure window, indicating that the timeframe for publishing detailed vulnerability information has since changed. Organizations running self managed GitLab deployments are advised to upgrade to the latest supported versions as soon as possible to reduce the risk posed by these security flaws.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.