[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-29778":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":72,"vuln_id":93,"name":94,"published":95,"updated":95},29778,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":68,"name":71},"Sniper",{"id":65,"codename":73,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":79,"references":80,"cvssv3":83,"epss_score":84,"epss_percentile":85,"cve":86,"in_cisa_catalog":9,"date":88,"software_type":89,"vendor":90,"product":90,"ptt_exploit_capabilities":91},null,"We found that the target server is vulnerable to CVE-2026-19478, a vulnerability in the GitLab GraphQL API that lets an unauthenticated attacker run methods the schema does not expose. The \u003Ccode>@gl_introduced\u003C\u002Fcode> directive exists so that an older instance tolerates a field belonging to a newer GitLab release. When a query asks for an unknown field and marks it with a version newer than the running instance, GitLab builds that field at runtime from the name the attacker chose. The field is built without a resolver, so the GraphQL library answers it by calling the method with the same name on the underlying object, and the directive is handled before the permission checks run. We have detected this vulnerability by reading a publicly visible project through \u003Ccode>\u002Fapi\u002Fv4\u002Fprojects?visibility=public\u003C\u002Fcode>, and then asking the GraphQL API for a field of that project that its schema does not define, marked with a future version. The server answered with the value of the method instead of rejecting the field, which confirms that a method chosen by the attacker was executed on the project record.","critical","The risk exists that a remote unauthenticated attacker can invoke internal methods of the application on public projects and users, read attributes that the API does not expose, and modify or delete projects and user accounts, which leads to loss of data and of the integrity of the hosted repositories.","GitLab is vulnerable to CVE-2026-19478, a vulnerability in the GraphQL API that lets an unauthenticated attacker run methods that the API is not meant to expose. A directive meant to keep older instances compatible with newer clients makes GitLab build a missing field at runtime, using the name supplied in the request, and answer it by calling the method with that name on the underlying record before any permission check is performed. Because this happens on objects that are readable by anyone, such as public projects and their users, a remote attacker can reach internal methods of the application and modify or delete public projects and user data.","Update GitLab to version 18.11.11, 19.0.8, 19.1.6 or 19.2.4, depending on the release series in use.","We recommend updating GitLab Community Edition or Enterprise Edition to version 18.11.11, 19.0.8, 19.1.6 or 19.2.4, depending on the release series in use, since these are the versions in which this vulnerability was fixed.",[81,82],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-19478","https:\u002F\u002Fdocs.gitlab.com\u002Freleases\u002Fpatches\u002Fpatch-release-gitlab-19-2-4-released\u002F",9.4,0.60204,0.99114,[87],"CVE-2026-19478","2026-08-17T00:00:00Z","DevOps Platform","GitLab",[92],"CUSTOM","NETSCAN-SNIPER-CVE-2026-19478","GitLab - Arbitrary Method Invocation","2026-09-29T00:00:00Z"]