Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-19478

GitLab GraphQL unauthenticated project deletion and modification

Critical GraphQL flaw in GitLab CE/EE lets unauthenticated attackers modify or delete public projects and user data. Patched; self-hosted instances need manual update.

cat cve-2026-19478.json
Vendor
GitLab
Product
GitLab Community Edition and Enterprise Edition
CVSS
9.4
EPSS (exploit probability)
N/A
Status
patched
Published

GitLab patched a critical-severity GraphQL vulnerability on August 17, 2026. An unauthenticated attacker who can reach the GraphQL endpoint can, under certain conditions, remotely modify or delete public projects and user data without any account credentials.

The flaw affects both Community Edition (CE) and Enterprise Edition (EE). GitLab.com (SaaS) has been patched by GitLab directly. Self-hosted instances require a manual update to the latest patched release.

Consult GitLab’s security release advisory for the specific affected version ranges and upgrade path.