CVE-2026-16494 – GitLab

CVSS 7.1 IMPORTANT Critical - Same Day Deployment

“A Critical GraphQL flaw can let unauthenticated attackers alter public projects, while several authorization and XSS issues weaken project and pipeline controls.”

GitLab fixes one Critical and six High-severity vulnerabilities across GitLab CE/EE. CVE-2026-19478 can allow an unauthenticated attacker to remotely modify or delete public projects and user data through a GraphQL directive. The CVSS score is 9.4, which is Critical severity.

CVE-2026-15216 and CVE-2026-15217 are analytics dashboard cross-site scripting flaws, each with a CVSS score of 8.7, High severity. CVE-2026-15423 can let a developer run CI/CD pipelines on protected branches without the required push permission, while CVE-2026-19228 can misattribute AI usage across namespaces; both score 8.5, High severity. CVE-2026-16494 scores 7.1 and can allow unauthorized project-setting changes, while CVE-2026-16627 scores 7.7 and can enable privilege escalation through unsafe HTML handling.

Key Details

Affected Product
Gitlab Gitlab
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.