CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Critical GitLab Flaw Exploited Shortly After Disclosure

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4751

As cited

Copy frozen at (site build).

vulnerabilities

Critical GitLab Flaw Exploited Shortly After Disclosure

CVE-2026-19478 affects GitLab and permits unauthenticated attackers to modify or delete public projects and user data. Active exploitation began shortly after the vulnerability became public.

Why it matters: GitLab instance administrators and users with public projects must patch immediately to prevent data loss and unauthorized modification; attackers are actively weaponizing this flaw.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical GitLab Flaw Exploited Shortly After Disclosure

CVE-2026-19478 affects GitLab and permits unauthenticated attackers to modify or delete public projects and user data. Active exploitation began shortly after the vulnerability became public.

Why it matters: GitLab instance administrators and users with public projects must patch immediately to prevent data loss and unauthorized modification; attackers are actively weaponizing this flaw.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical GitLab Flaw Exploited Shortly After Disclosure

CVE-2026-19478 affects GitLab and permits unauthenticated attackers to modify or delete public projects and user data. Active exploitation began shortly after the vulnerability became public.

Why it matters: GitLab instance administrators and users with public projects must patch immediately to prevent data loss and unauthorized modification; attackers are actively weaponizing this flaw.

VendorsGitLab
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary