AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 22 Aug, 20:12

Critical GitLab flaw (CVE-2026-19478) exploited within days of public disclosure

A critical, unauthenticated code injection flaw in GitLab, tracked as CVE-2026-19478, is being actively exploited just days after disclosure, letting attackers delete public repositories with no login required. Per The Hacker News and Help Net Security.

GitLab $GTLB patched a critical code injection vulnerability, CVE-2026-19478 (CVSS 9.4), that lets an unauthenticated attacker modify or delete public projects and user data on self-managed GitLab Community Edition and Enterprise Edition servers via a GraphQL directive, with no credentials or user interaction required. Security firm watchTowr said it reproduced the exploit within minutes of GitLab's disclosure and observed in-the-wild exploitation against its honeypot network; watchTowr's Jake Knott said AI-enabled attackers are compressing the time from disclosure to exploitation. Beyond deleting public projects, attackers can delete entire repositories, forge merge records to make it look like a fix landed when it did not, and ban project maintainers. GitLab.com and GitLab Dedicated were already on the patched version; self-managed instances on versions before 18.11.11, 19.0.8, 19.1.6 or 19.2.4 needed to upgrade after GitLab's out-of-band patch release on August 17, 2026. Sources: The Hacker News, Help Net Security.

#cyber
Published on