Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. 🔴 Critical: Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

🔴 Critical: Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
cve-2026-19478gitlab
1 Posts 1 Posters 7 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    GitLab shipped security updates this week to close off a critical vulnerability in both its Community Edition (CE) and Enterprise Edition (EE) offerings. Under specific configurations, the flaw could allow an unauthenticated attacker to remotely alter or delete public projects and associated user data.

    The issue, tracked as CVE-2026-19478, carries a CVSS score of 9.4 and has been rated Critical by GitLab. The root cause resides in the GraphQL API, where improper authorization checks open the door for exploitation.

    • Affected versions include all releases of GitLab CE/EE prior to the latest patched versions.
    • Upgrading to the newest security release is strongly recommended to mitigate the risk.
    • Administrators should review their instance logs for any unauthorized GraphQL queries targeting public projects.
    • If an upgrade cannot be performed immediately, restricting network access to the GitLab instance is advised as a temporary control.

    Given the severity score and the fact that authentication is not required to trigger the issue, this patch should be treated as urgent. Public-facing instances are particularly exposed, and the window for attackers to exploit the flaw before widespread adoption of the update is likely narrow.

    Source: The Hacker News

    Has your team already patched your GitLab instance, or are you still assessing exposure to this GraphQL flaw?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World