GitLab GraphQL unauthenticated project deletion and modification
Critical GraphQL flaw in GitLab CE/EE lets unauthenticated attackers modify or delete public projects and user data. Patched; self-hosted instances need manual update.
- Vendor
- GitLab
- Product
- GitLab Community Edition and Enterprise Edition
- CVSS
- 9.4
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
GitLab patched a critical-severity GraphQL vulnerability on August 17, 2026. An unauthenticated attacker who can reach the GraphQL endpoint can, under certain conditions, remotely modify or delete public projects and user data without any account credentials.
The flaw affects both Community Edition (CE) and Enterprise Edition (EE). GitLab.com (SaaS) has been patched by GitLab directly. Self-hosted instances require a manual update to the latest patched release.
Consult GitLab’s security release advisory for the specific affected version ranges and upgrade path.
