2026-08-19HIGHexploitedGitLab breaks its own release cadence for a pre-auth flaw whose impact is destruction, not disclosure
GitLab CE/EE, cross-site request forgery in the GraphQL multiplex query handler allowing mutations to be executed via GET requests through improper request validation (CVSS 7.1, vendor-assigned). Fixed in the same 2026-08-17 out-of-band release as CVE-2026-19478.
cve · CVE-2026-19650
Coverage
1
first 2026-08-19 → last 2026-08-19
Latest activity
2026-08-22
GitLab breaks its own release cadence for a pre-auth flaw whose impact is destruction, not disclosure
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology, finance · regions: europe
Sources cited
5
5 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-19650, newest first. Check the date before acting on an older one.
- Upgrade every self-managed GitLab instance to 18.11.11, 19.0.8, 19.1.6 or 19.2.4 for its line; GitLab states these releases carry no new migrations and should need no downtime on multi-node deployments, which removes the usual reason to defer.2026-08-19CVE-2026-19478 +1
- Search web and reverse-proxy access logs for requests to the GraphQL API endpoint carrying the string2026-08-19CVE-2026-19478 +1
@gl_introduced, and treat any unauthenticated request to that endpoint as a probe or an exploitation attempt. Because the flaw's impact is modification and deletion rather than disclosure, pair the log search with a check of project and user-data integrity against backups over the window from 2026-08-17 onward, on any self-managed instance that was internet-reachable and unpatched.
Defender insights
What each entry about CVE-2026-19650 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ImpactData Destruction
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-19/cve-2026-19478-gitlab-graphql-unauth-data-destruction · ATT&CK page ↗
Impact TA0040
T1485Data Destruction×1
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.
Evidence: 2026-08-19/cve-2026-19478-gitlab-graphql-unauth-data-destruction · ATT&CK page ↗
Entries about GitLab CE/EE, cross-site request forgery in the GraphQL multiplex query handler allowing mutations to be executed via GET requests through improper request validation (CVSS 7.1, vendor-assigned). Fixed in the same 2026-08-17 out-of-band release as CVE-2026-19478. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- GitLab×1
- GitLab CE/EE, code injection via a GraphQL directive allowing an unauthenticated user to remotely modify or delete public projects and user data (CVSS 9.4, vendor-assigned). Fixed out of band on 2026-08-17 in 18.11.11 / 19.0.8 / 19.1.6 / 19.2.4. Actively exploited: WatchTowr honeypots caught in-the-wild attempts ~2 days after the patch (SecurityWeek 2026-08-20); NCSC-CH amended its advisory 2026-08-21; covered by entries/2026-08-22/cve-2026-19478-gitlab-honeypot-exploitation-confirmed. Not on CISA KEV as of 2026-08-24.×1
Where this entity is cited
Source distribution
- cert.ssi.gouv.fr1 (20%)
- csoonline.com1 (20%)
- docs.gitlab.com1 (20%)
- security-hub.ncsc.admin.ch1 (20%)
- securityweek.com1 (20%)
External references
All cited sources (5)
- docs.gitlab.comprimaryGitLabhttps://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
- cert.ssi.gouv.frCERT-FR / ANSSIhttps://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1037/
- csoonline.comCSO Onlinehttps://www.csoonline.com/article/4211140/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.html
- security-hub.ncsc.admin.chNCSC Switzerlandhttps://security-hub.ncsc.admin.ch/#/posts/12856
- securityweek.comSecurityWeekhttps://www.securityweek.com/critical-gitlab-flaw-exploited-shortly-after-disclosure/