Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical GraphQL Vulnerability (CVE‑2026‑19478) Enables Unauthenticated Modification/Deletion of Public GitLab Projects

GitLab’s self‑managed installations are vulnerable to CVE‑2026‑19478, a critical GraphQL flaw that lets unauthenticated attackers modify or delete public projects. The issue underscores the need for robust SOC 2 access‑control monitoring and rapid patch management.

LiveThreat™ Intelligence · 📅 August 23, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

Critical GraphQL Vulnerability (CVE‑2026‑19478) Enables Unauthenticated Modification/Deletion of Public GitLab Projects

What It Is — A critical flaw in GitLab’s GraphQL API (CVE‑2026‑19478) allows an attacker with no credentials to issue a specially‑crafted directive that can modify or delete public projects and associated user data.

Exploitability — Actively exploited in the wild; a public proof‑of‑concept exists. CVSS 9.4 (Critical).

Affected Products — Self‑managed GitLab installations on versions 18.2‑18.10 (unpatched) and earlier; patched releases are 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls – The flaw bypasses authentication, directly violating the CC6.1 (Logical Access) and CC6.2 (User Access Management) criteria.
  • Evidence of Due Diligence – Continuous monitoring of patch status and API exposure demonstrates a mature control environment that auditors expect.
  • Defensible Audit Trail – Documenting remediation steps (patches, API restrictions, log reviews) provides concrete evidence for the Security principle during SOC 2 examinations.

Recommended Actions

  • Upgrade all self‑managed GitLab instances to the patched versions (19.2.4, 19.1.6, 19.0.8, or 18.11.11) immediately.
  • If upgrade is not possible, block unauthenticated access to /api/graphql at the perimeter firewall or WAF.
  • Disable public repositories where business needs allow.
  • Enable detailed logging for GraphQL requests and audit for the @gl_introduced directive.
  • Incorporate the patch‑status check into your continuous compliance monitoring pipeline.

Source: Security Affairs – GitLab Warns of Active Exploitation of Critical GraphQL Flaw

📰 Original Source
https://securityaffairs.com/197622/hacking/gitlab-warns-of-active-exploitation-of-critical-graphql-flaw.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →