Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical WordPress Plugin Bug Exposes 600,000 Sites to File Upload Attacks
August 18, 2026
Critical VMware ESXi Vulnerability Lets Attackers Gain Root and Persistent SSH Access
August 18, 2026
Critical GitLab GraphQL Vulnerability Lets Attackers Delete Projects
August 18, 2026
Home/Vulnerabilities/Critical GitLab GraphQL Vulnerability Lets Attackers Delete Projects
Vulnerabilities

Critical GitLab GraphQL Vulnerability Lets Attackers Delete Projects

Key Takeaways A critical GraphQL vulnerability (CVE-2026-19478) in GitLab allows unauthenticated attackers to modify or delete public projects and user data. The flaw impacts GitLab Community Edition...

Jennifer sherman
Jennifer sherman
August 18, 2026 3 Min Read
2 0

Key Takeaways

  • A critical GraphQL vulnerability (CVE-2026-19478) in GitLab allows unauthenticated attackers to modify or delete public projects and user data.
  • The flaw impacts GitLab Community Edition (CE) and Enterprise Edition (EE) across multiple versions.
  • A CVSS score of 9.4 categorizes this as a critical severity issue.
  • Patches were released on August 17, 2026, in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

GitLab has issued urgent security updates to address a severe GraphQL vulnerability that could enable unauthenticated attackers to remotely manipulate or delete public projects and associated user data. This critical flaw highlights the ongoing need for vigilant patch management in self-managed instances.

Table Of Content

  • Key Takeaways
  • GitLab GraphQL Vulnerability Details
  • Additional Vulnerability Addressed
  • What You Should Do

The vulnerability, identified as CVE-2026-19478, impacts both GitLab Community Edition (CE) and Enterprise Edition (EE) installations across several supported release branches. Remedial patches were made available on August 17, 2026, with the release of GitLab versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

GitLab strongly advises administrators of self-managed instances to apply these updates without delay. Users of GitLab.com and GitLab Dedicated platforms are already protected, as these services have been updated to the patched versions and require no customer action.

GitLab GraphQL Vulnerability Details

CVE-2026-19478 is characterized as a code injection vulnerability residing within a GraphQL directive. This flaw, under specific conditions, could be exploited by a remote, unauthenticated attacker to execute unauthorized actions against public GitLab resources. The severity of this issue is underscored by its CVSS score of 9.4 out of 10, placing it firmly in the critical category.

The potential ramifications of successful exploitation include the modification or complete deletion of public projects and user data, all without the need for a valid GitLab account. The CVSS vector indicates that exploitation can occur over the network, requires minimal attack complexity, demands no special privileges or user interaction, and can lead to significant impacts on both integrity and availability.

Consequently, unpatched GitLab servers exposed to the internet present an appealing target for opportunistic attackers and malicious actors seeking to disrupt public software development infrastructure. All GitLab CE and EE releases from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 are susceptible.

Organizations running any of the affected releases must prioritize this issue as an emergency patching task, particularly if public projects are enabled. GitLab has credited security researcher hiimguardian for responsibly disclosing this vulnerability via its HackerOne bug bounty program. Further technical specifics are expected to remain confidential until GitLab’s standard disclosure policy permits the related vulnerability issue to be made public.

Additional Vulnerability Addressed

The recent security release also fixes CVE-2026-19650, which is a high-severity cross-site request forgery (CSRF) vulnerability found in GitLab’s GraphQL multiplex query handler. This particular flaw could allow unauthenticated users to execute GraphQL mutations through GET requests if request validation is improperly handled. This issue carries a CVSS score of 7.1 and affects the same range of GitLab versions as CVE-2026-19478.

What You Should Do

  • Immediate Upgrade: Apply the latest patches by upgrading to GitLab 19.2.4, 19.1.6, 19.0.8, or 18.11.11, corresponding to your deployed branch.
  • Prioritize Internet-Facing Instances: Focus patching efforts on any GitLab instances accessible from the internet, as the critical vulnerability can be exploited remotely without authentication.
  • Monitor Audit Logs: Review GitLab audit logs for any suspicious activity, including unexpected modifications to public repositories, deleted projects, altered memberships, unusual GraphQL activity, or unexplained changes to user data.
  • Understand Upgrade Impact: While GitLab states these updates contain no new database migrations and multi-node deployments should not require downtime, be aware that default Omnibus update behavior might briefly stop and restart services during reconfiguration. Plan accordingly.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerPatchSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Best Network Sandboxing Solutions for 2026

Next Post

Critical VMware ESXi Vulnerability Lets Attackers Gain Root and Persistent SSH Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Claude AI code enabled ransomware gang to steal LDAP passwords, backdoor VPNs
August 18, 2026
Pokémon Center Data Breach Exposes Customer PII to Hackers
August 18, 2026
Best Software-Defined Perimeter (SDP) Solutions of 2024
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us