Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.
The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring credentials, user interaction, or obscure configuration.
The following versions of GitLab Community Edition (CE) and Enterprise Edition (EE) are affected by the flaw -
18.2 before 18.11.11






