A newly disclosed critical security vulnerability in GitLab has reportedly moved into active exploitation shortly after public disclosure, according to cybersecurity firm watchTowr. The vulnerability, tracked as CVE-2026-19478 with a CVSS score of 9.4, affects GitLab Community Edition (CE) and Enterprise Edition (EE) and could allow unauthenticated attackers to modify or delete publicly accessible GitLab projects under specific conditions.
The flaw is related to code injection through a GraphQL directive and does not require attacker credentials, user interaction, or unusual system configurations to be exploited. Under affected conditions, an attacker could rewrite project data, impacting the integrity of publicly available repositories hosted on vulnerable GitLab instances. GitLab has identified multiple affected versions, including GitLab 18.2 versions before 18.11.11, GitLab 19.0 versions before 19.0.8, GitLab 19.1 versions before 19.1.6, and GitLab 19.2 versions before 19.2.4. GitLab disclosed the issue earlier this week and released security updates to address the vulnerability. The fixes have been included in GitLab CE and EE versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. The company highlighted that the vulnerability could be triggered through a GraphQL directive, making it important for organizations operating affected self-hosted GitLab environments to apply the available patches.
watchTowr said it was able to reproduce the vulnerability within minutes of its disclosure and later observed exploitation attempts targeting its honeypot network. Jake Knott, principal security researcher at watchTowr, said the incident reflects a growing challenge where artificial intelligence enabled attackers can reduce the time between vulnerability disclosure and exploitation. He noted that organizations delaying updates until the next regular patch cycle may face increased exposure. The cybersecurity firm advised organizations that have not yet installed the security updates to review web logs for requests containing “@gl_introduced” and investigate possible signs of scanning activity or exploitation attempts. watchTowr also highlighted that the potential impact of the vulnerability extends beyond modifying or deleting public projects. According to the firm, attackers could delete complete repositories, create false merge records that make it appear as though a security fix was applied, and remove project maintainers from affected environments.
The exploitation activity associated with CVE-2026-19478 highlights the increasing speed at which security flaws are being analyzed and targeted after disclosure. Organizations using internet-facing self-hosted GitLab instances are advised to upgrade to patched releases as soon as possible. If immediate updating is not possible, administrators can reduce exposure by restricting unauthenticated access to the “/api/graphql” endpoint or removing public repository access until the security update is deployed.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





