top of page

Critical GitLab vulnerability actively exploited: Severe risk to the supply chain

Just days after being publicly disclosed, a critical security vulnerability in the GitLab platform has rapidly been targeted by attackers. Alarmingly, threat actors can exploit this flaw to tamper with or delete data without requiring any authentication or user account.

CVE-2026-19478 vulnerability and its dangerous impact

Tracked as CVE-2026-19478, this security issue carries a critical CVSS score of 9.4. It is an injection flaw originating from GraphQL directives, allowing unauthenticated remote attackers to modify or delete public projects and user information.

The GitLab team released patches on August 17 for both Community Edition and Enterprise Edition, covering versions: 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

According to security researcher Jake Knott from attack surface management firm WatchTowr, with just a single HTTP payload (request), attackers can perform a series of destructive actions without needing an account, user interaction, or complex configurations:

  • Wipe publicly accessible repositories.

  • Change project status.

  • Revoke administrator access.

  • Forge code approval details.

In-the-wild exploitation and urgent recommendations

Events unfolded rapidly. On August 18, WatchTowr warned that it took them only a few minutes to recreate the exploit based on available technical descriptions and patches. The assistance of artificial intelligence (AI) tools has further accelerated the research timeframe for attackers.

By Wednesday, WatchTowr's honeypots recorded the first active exploitation attempts targeting CVE-2026-19478.

For organizations running self-managed GitLab instances that have not yet updated, experts recommend:

  • Urgently upgrade to a patched version as soon as possible.

  • Restrict unauthenticated access to the /api/graphql endpoint or disable public access to repositories.

  • Immediately check web access logs for the keyword string @gl_introduced to detect early signs of probing or attack.

Severe threat to the software supply chain

Assessing the impact, Patrick Münch, Co-founder and CSO of Mondoo, noted that this vulnerability could trigger a new wave of supply chain attacks.

Typically, threat actors must find ways to bypass code review processes—a step that is difficult to manipulate. However, CVE-2026-19478 enables them to forge approvals with ease. Malicious code could effortlessly pass inspection under the identity of a trusted team member.

While data deletion forces businesses to spend time on recovery, compromised trust in source code leaves long-lasting consequences, threatening the security of every future software release.

The lightning-fast exploitation speed in this incident highlights a new reality in cybersecurity: the window of safety between flaw discovery and active exploitation is shrinking drastically. Proactively applying security patches as soon as they are released is the key defense for safeguarding systems.

Reference: SecurityWeek

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page