August 18, 2026
gitlab.jpg

I show You how To Make Huge Profits In A Short Time With Cryptos!

Swati KhandelwalAug 17, 2026Vulnerability / DevOps

GitLab has launched safety updates to handle a important vulnerability impacting its Group Version (CE) and Enterprise Version (EE) software program that, underneath sure situations, may permit an unauthenticated attacker to remotely modify or delete public tasks and consumer information.

The flaw, tracked as CVE-2026-19478, has been rated Crucial by GitLab and assigned a CVSS rating of 9.4.

Launched on August 17, 2026, the important patch launch arrived exterior the corporate’s ordinary schedule of twice-monthly updates on the second and fourth Wednesdays, 5 days after a routine patch launch that carried no critical-rated points.

Solely self-managed installations have to act. The fixes can be found in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

“GitLab.com and GitLab Devoted are already operating the patched model. GitLab.com and GitLab Devoted clients don’t have to take motion,” the corporate stated.

The next variations are affected –

  • All variations from 18.2 earlier than 18.11.11
  • 19.0 earlier than 19.0.8
  • 19.1 earlier than 19.1.6
  • 19.2 earlier than 19.2.4

The fixes don’t prolong to the 18.2 by way of 18.10 branches, which fall contained in the affected vary.

“GitLab has remediated a problem that underneath sure situations may permit an unauthenticated consumer to remotely modify or delete public tasks and consumer information by way of a GraphQL directive,” GitLab stated.

The CVSS vector printed for the flaw signifies that it may be exploited over a community by an attacker holding no credentials, and with none motion on the a part of a sufferer.

GitLab has not named the GraphQL directive concerned or specified what the situations vital for exploitation are.

The advisory discloses no exploitation of both flaw, and no public exploit code for them has surfaced on GitHub as of August 18, 2026.

The second concern fastened within the launch, CVE-2026-19650, has been rated Excessive by GitLab with a CVSS rating of seven.1, and considerations a cross-site request forgery (CSRF) weak spot within the GraphQL multiplex question handler.

Not like the important flaw, it requires consumer interplay to work.

“GitLab has remediated a problem that underneath sure situations may have allowed an unauthenticated consumer to execute mutations by way of GET requests as a result of improper request validation in GraphQL multiplex question dealing with,” the corporate stated.

The corporate stated the replace introduces no new migrations and isn’t anticipated to require downtime on multi-node deployments.

The disclosure follows a July 2026 report by which researchers printed working exploit code for a separate GitLab flaw affecting self-managed servers.

GitLab didn’t instantly reply to a request for remark.

The corporate stated it makes the problems detailing every vulnerability public on its concern tracker 90 days after the discharge that patched them. GitLab’s June 10, 2026 patch launch put that window at 30 days.

That locations technical particulars of each flaws at round mid-November 2026.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *