HackerFeeds

CyberSecurity News

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

The Hacker News
· August 21, 2026

AI summary

A security flaw in GitLab, identified as CVE-2026-19478, has been exploited by attackers just days after its public disclosure. The vulnerability has a CVSS score of 9.4 and allows unauthenticated attackers to modify or delete publicly accessible GitLab projects under certain conditions. This is made possible by a code injection vulnerability that enables data rewriting without authentication. The rapid exploitation of this flaw was reported by watchTowr. The vulnerability poses a significant risk due to its high CVSS score and potential for data modification. Attackers can exploit this flaw to alter or delete project data without needing authentication.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.