Users should immediately upgrade GitLab to the patched version as specified in the GitLab security advisory. Review GitLab's recommended upgrade paths for Community Edition and Enterprise Edition. Monitor official GitLab channels for any additional guidance or out-of-band patches.
Quick answers
What is CVE-2026-19478?
Users should immediately upgrade GitLab to the patched version as specified in the GitLab security advisory. Review GitLab's recommended upgrade paths for Community Edition and Enterprise Edition. Monitor official GitLab channels for any additional guidance or out-of-band patches.
How severe is CVE-2026-19478?
critical, CVSS 9.4
Is CVE-2026-19478 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-19478 be mitigated?
Users should immediately upgrade GitLab to the patched version as specified in the GitLab security advisory. Review GitLab's recommended upgrade paths for Community Edition and Enterprise Edition. Monitor official GitLab channels for any additional guidance or out-of-band patches.
CVSS
9.4
Vendor
GitLab
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
GitLab Community Edition, GitLab Enterprise Edition
Mitigation
Users should immediately upgrade GitLab to the patched version as specified in the GitLab security advisory. Review GitLab's recommended upgrade paths for Community Edition and Enterprise Edition. Monitor official GitLab channels for any additional guidance or out-of-band patches.
GitLab has addressed a critical GraphQL vulnerability tracked as CVE-2026-19478, which could allow unauthenticated attackers to remotely modify or delete public projects and associated user data. The flaw received a CVSS score of 9.4 and affects both Community Edition and Enterprise Edition. Patches were coordinatedly released on August 17, 2026.