/Vulnerability Library

GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method Invocation

CVE-2026-19478
Verified

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Severity

Critical

CVSS Score

9.4

Exploit Probability

60%

Affected Product

gitlab

Published Date

August 18, 2026

Template Author

0x_akoko, dhiyaneshdk

CVE-2026-19478.yaml
9.4Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CVE ID:
cve-2026-19478
CWE ID:
cwe-94

References

https://www.cve.org/CVERecord?id=CVE-2026-19478https://github.com/davkharrr/CVE-2026-19478-PoChttps://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/https://gitlab.com/gitlab-org/gitlab/-/work_items/611377

Remediation Steps

Upgrade GitLab to version 18.11.11, 19.0.8, 19.1.6, or 19.2.4 or later.