Critical GitLab GraphQL Vulnerability Lets Attackers Delete Projects
Key Takeaways A critical GraphQL vulnerability (CVE-2026-19478) in GitLab allows unauthenticated attackers to modify or delete public projects and user data. The flaw impacts GitLab Community Edition...
Key Takeaways
- A critical GraphQL vulnerability (CVE-2026-19478) in GitLab allows unauthenticated attackers to modify or delete public projects and user data.
- The flaw impacts GitLab Community Edition (CE) and Enterprise Edition (EE) across multiple versions.
- A CVSS score of 9.4 categorizes this as a critical severity issue.
- Patches were released on August 17, 2026, in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.
GitLab has issued urgent security updates to address a severe GraphQL vulnerability that could enable unauthenticated attackers to remotely manipulate or delete public projects and associated user data. This critical flaw highlights the ongoing need for vigilant patch management in self-managed instances.
Table Of Content
The vulnerability, identified as CVE-2026-19478, impacts both GitLab Community Edition (CE) and Enterprise Edition (EE) installations across several supported release branches. Remedial patches were made available on August 17, 2026, with the release of GitLab versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.
GitLab strongly advises administrators of self-managed instances to apply these updates without delay. Users of GitLab.com and GitLab Dedicated platforms are already protected, as these services have been updated to the patched versions and require no customer action.
GitLab GraphQL Vulnerability Details
CVE-2026-19478 is characterized as a code injection vulnerability residing within a GraphQL directive. This flaw, under specific conditions, could be exploited by a remote, unauthenticated attacker to execute unauthorized actions against public GitLab resources. The severity of this issue is underscored by its CVSS score of 9.4 out of 10, placing it firmly in the critical category.
The potential ramifications of successful exploitation include the modification or complete deletion of public projects and user data, all without the need for a valid GitLab account. The CVSS vector indicates that exploitation can occur over the network, requires minimal attack complexity, demands no special privileges or user interaction, and can lead to significant impacts on both integrity and availability.
Consequently, unpatched GitLab servers exposed to the internet present an appealing target for opportunistic attackers and malicious actors seeking to disrupt public software development infrastructure. All GitLab CE and EE releases from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 are susceptible.
Organizations running any of the affected releases must prioritize this issue as an emergency patching task, particularly if public projects are enabled. GitLab has credited security researcher hiimguardian for responsibly disclosing this vulnerability via its HackerOne bug bounty program. Further technical specifics are expected to remain confidential until GitLab’s standard disclosure policy permits the related vulnerability issue to be made public.
Additional Vulnerability Addressed
The recent security release also fixes CVE-2026-19650, which is a high-severity cross-site request forgery (CSRF) vulnerability found in GitLab’s GraphQL multiplex query handler. This particular flaw could allow unauthenticated users to execute GraphQL mutations through GET requests if request validation is improperly handled. This issue carries a CVSS score of 7.1 and affects the same range of GitLab versions as CVE-2026-19478.
What You Should Do
- Immediate Upgrade: Apply the latest patches by upgrading to GitLab 19.2.4, 19.1.6, 19.0.8, or 18.11.11, corresponding to your deployed branch.
- Prioritize Internet-Facing Instances: Focus patching efforts on any GitLab instances accessible from the internet, as the critical vulnerability can be exploited remotely without authentication.
- Monitor Audit Logs: Review GitLab audit logs for any suspicious activity, including unexpected modifications to public repositories, deleted projects, altered memberships, unusual GraphQL activity, or unexplained changes to user data.
- Understand Upgrade Impact: While GitLab states these updates contain no new database migrations and multi-node deployments should not require downtime, be aware that default Omnibus update behavior might briefly stop and restart services during reconfiguration. Plan accordingly.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.