CVE-2026-16494 – GitLab
“A Critical GraphQL flaw can let unauthenticated attackers alter public projects, while several authorization and XSS issues weaken project and pipeline controls.”
GitLab fixes one Critical and six High-severity vulnerabilities across GitLab CE/EE. CVE-2026-19478 can allow an unauthenticated attacker to remotely modify or delete public projects and user data through a GraphQL directive. The CVSS score is 9.4, which is Critical severity.
CVE-2026-15216 and CVE-2026-15217 are analytics dashboard cross-site scripting flaws, each with a CVSS score of 8.7, High severity. CVE-2026-15423 can let a developer run CI/CD pipelines on protected branches without the required push permission, while CVE-2026-19228 can misattribute AI usage across namespaces; both score 8.5, High severity. CVE-2026-16494 scores 7.1 and can allow unauthorized project-setting changes, while CVE-2026-16627 scores 7.7 and can enable privilege escalation through unsafe HTML handling.
Key Details
- Affected Product
- Gitlab Gitlab
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-862