GitLab code injection CVE-2026-19478 sees active exploitation fast
Source headline: GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
Intelligence Summary
WatchTowr reports that GitLab vulnerability CVE-2026-19478 is being actively exploited within days of public disclosure. The flaw has a CVSS score of 9.4 and is described as a code injection issue. It can allow an unauthenticated attacker to modify or delete publicly accessible GitLab projects. Under certain conditions, the attacker can also rewrite project data. No workaround or patch details are provided in the supplied text. Apply urgent mitigation and check your GitLab exposure for CVE-2026-19478 immediately.
Recommended Action
Check whether your GitLab deployment is affected by CVE-2026-19478 (CVSS 9.4) and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.