A newly disclosed security flaw in GitLab, CVE-2026-19478, has been actively exploited within days of its public disclosure. The vulnerability carries a CVSS score of 9.4 and enables code injection attacks.
- A critical vulnerability CVE-2026-19478 has been disclosed in GitLab.
- The CVSS score is 9.4, indicating high severity.
- An unauthenticated attacker can modify or delete publicly accessible GitLab projects.
According to watchTowr, the newly disclosed GitLab security flaw CVE-2026-19478 is already being actively exploited just days after its public disclosure. This code‑injection vulnerability allows an unauthenticated attacker, under certain conditions, to rewrite or delete data in publicly accessible projects.
Vulnerability Details
CVE‑2026‑19478 enables code injection that lets an unauthenticated attacker alter, delete, or rewrite data in public GitLab repositories. With a CVSS rating of 9.4, the flaw is classified as critical.
Why This Matters
BozokMedia analysis shows that such vulnerabilities pose significant threats across development and production environments, especially where open‑source repositories are heavily leveraged.
"GitLab users should apply the latest patches immediately and review access controls on all public projects." - Cybersecurity expert
Frequently Asked Questions
- How was the GitLab security flaw discovered?
- What steps can users take to mitigate this risk?