Skip to content
arrow-alt-circle-up icon

Cyber Incident?

arrow-alt-circle-up icon

Call 00800 1744 0000

arrow-alt-circle-up icon

See all Threat Responses

Dutch follows English

A critical vulnerability in GitLab allows attackers to remotely modify or delete public projects and user data without any authentication. Patches are available and should be applied immediately.

Description

On August 17, GitLab has released patches[1] for a critical code injection vulnerability (CVE-2026-19478 [2]) in their platform. This vulnerability affects GitLab Community Edition (CE) and Enterprise Edition (EE) versions 18.2 through 19.2.3. The vulnerability exists in GitLab's GraphQL interface, which is a component that handles data queries and modifications. Under certain conditions, attackers can exploit this flaw to remotely modify or delete public projects and user data without needing any login credentials.

Technical details are available [3], making immediate exploitation likely.

Impact

We estimate the impact of this vulnerability as High.

This vulnerability allows attackers to compromise the integrity and availability of your source code repositories. Since GitLab typically stores your organization's source code, CI/CD configurations, and development workflows, a successful attack could compromise your software development process and any applications built from the affected repositories.

Risk

We estimate the risk of this vulnerability as High.

This vulnerability has a CVSS score of 9.4 out of 10, classified as CRITICAL. The risk is exceptionally high because attackers do not need any credentials to exploit this vulnerability. GitLab is commonly used as a public-facing service, making many installations vulnerable.

The technical details of this vulnerability have been disclosed through security research platforms, increasing the likelihood of active exploitation.

Mitigation

GitLab has released security patches that fix this vulnerability. You must update your GitLab installation to one of the following patched versions:

  • Version 18.11.11 (if running GitLab 18.x)
  • Version 19.0.8 (if running GitLab 19.0.x)
  • Version 19.1.6 (if running GitLab 19.1.x)
  • Version 19.2.4 (if running GitLab 19.2.x)

What should you do?

If you operate GitLab servers, you should patch them immediately to the versions listed above. Prioritize patching internet-facing instances.

After patching, review your GitLab audit logs for any suspicious GraphQL activity that occurred before the patch was applied [4]. Check your public projects for unauthorized modifications, using the platform’s audit logs [5].

If you cannot patch immediately, implement network-level access controls to restrict who can reach your GitLab instance until patching is complete.

What will Northwave do?

Vulnerability Management customers will be informed in case vulnerable systems are detected in their infrastructure.

We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can call us by phone or send us an email if you would like additional information.


E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000

Disclaimer applies, see below.

Sources

[1]: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/  

[2]: https://www.cve.org/CVERecord?id=CVE-2026-19478

[3]: https://hackerone.com/reports/3926431

[4]: https://docs.gitlab.com/administration/logs/#graphql_jsonlog

[5]: https://docs.gitlab.com/api/audit_events/


Een kritieke kwetsbaarheid in GitLab stelt aanvallers in staat om op afstand openbare projecten en gebruikersgegevens te wijzigen of te verwijderen zonder enige vorm van authenticatie. Er zijn patches beschikbaar die onmiddellijk moeten worden geïnstalleerd.

Beschrijving

Op 17 augustus heeft GitLab patches[1] uitgebracht voor een kritieke code-injectiekwetsbaarheid (CVE-2026-19478 [2]) in hun platform. Deze kwetsbaarheid treft GitLab Community Edition (CE) en Enterprise Edition (EE) versies 18.2 tot en met 19.2.3.

De kwetsbaarheid bevindt zich in de GraphQL-interface van GitLab, een component die verantwoordelijk is voor het verwerken van opvragen en wijzigen van data in het platform. Onder bepaalde omstandigheden kunnen aanvallers deze kwetsbaarheid misbruiken om op afstand openbare projecten en gebruikersgegevens te wijzigen of te verwijderen zonder inloggegevens nodig te hebben.

Technische details zijn inmiddels openbaar beschikbaar[3], waardoor onmiddellijke misbruik van deze kwetsbaarheid waarschijnlijk is.

Impact

Wij schatten de impact van deze kwetsbaarheid als Hoog in.

Deze kwetsbaarheid stelt aanvallers in staat om de integriteit en beschikbaarheid van uw broncoderepositories aan te tasten. Omdat GitLab vaak de broncode, CI/CD-configuraties en ontwikkelprocessen van uw organisatie bevat, kan een succesvolle aanval gevolgen hebben voor uw softwareontwikkelingsproces en voor alle applicaties die vanuit de getroffen repositories worden gebouwd.

Risico

Wij schatten het risico van deze kwetsbaarheid als Hoog in.

Deze kwetsbaarheid heeft een CVSS-score van 9,4 op 10 en is geclassificeerd als CRITICAL. Het risico is uitzonderlijk hoog omdat aanvallers geen enkele vorm van authenticatie nodig hebben om misbruik te maken van deze kwetsbaarheid. GitLab wordt vaak als publiek toegankelijke dienst ingezet, waardoor veel installaties kwetsbaar zijn.

De technische details van deze kwetsbaarheid zijn openbaar gemaakt via beveiligingsonderzoeksplatformen, wat de kans op actieve exploitatie verder vergroot.

Mitigatie

GitLab heeft patches uitgebracht die deze kwetsbaarheid verhelpen. Update uw GitLab installatie naar een van de volgene versies:

  • Versie 18.11.11 (indien u GitLab 18.x gebruikt)
  • Versie 19.0.8 (indien u GitLab 19.0.x gebruikt)
  • Versie 19.1.6 (indien u GitLab 19.1.x gebruikt)
  • Versie 19.2.4 (indien u GitLab 19.2.x gebruikt)

Wat moet u doen?

Als u GitLab-servers beheert, patch deze dan onmiddelijk naar de hierboven genoemde versies. Geef daarbij prioriteit aan servers die vanuit het internet toegankelijk zijn.

Controleer na het installeren van de patches uw GitLab-auditlogs op verdachte GraphQL-activiteiten die hebben plaatsgevonden voordat de patch werd toegepast [4]. Controleer daarnaast uw openbare projecten op ongeautoriseerde wijzigingen met behulp van de audit logs [5].

Als u niet direct kunt patchen, implementeer dan netwerkgebaseerde toegangsbeperkingen om te beperken wie toegang heeft tot uw GitLab-instantie totdat de updates zijn geïnstalleerd.

Wat doet Northwave?

Northwave informeert Vulnerability Management klanten wanneer in hun infrastructuur kwetsbare systemen worden ontdekt.

Northwave houdt de ontwikkelingen omtrent deze kwetsbaarheid in de gaten. Als er belangrijke nieuwe informatie omtrent deze dreiging bekend wordt, stellen wij u hiervan op de hoogte. Als u behoefte heeft aan extra informatie zijn we zowel telefonisch als via email bereikbaar.

E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000

Disclaimer van toepassing, zie onderaan.

Bronnen

[1]: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/

[2]: https://www.cve.org/CVERecord?id=CVE-2026-19478

[3]: https://hackerone.com/reports/3926431

[4]: https://docs.gitlab.com/administration/logs/#graphql_jsonlog

[5]: https://docs.gitlab.com/api/audit_events/

Disclaimer

Northwave has made every effort to make this information accurate and reliable. However, the information provided is without warranty of any kind and its use is at the sole risk of the user. Northwave does not accept any responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided. We will not be liable for any loss or damage of whatever nature, direct or indirect, consequential or other, whether arising in contract, tort or otherwise, which may arise as a result of your use of, or inability to use, this information or any additional information provided by us in direct or indirect relation to the information provided here.
.