Patch released GitLab CE web-app GitLab EE GitLab rce
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
CVE Tools coverage
GitLab has issued an out-of-cycle security patch for Community Edition and Enterprise Edition to fix critical vulnerability CVE-2026-19478. Rated 9.4 by the vendor, this flaw allows unauthenticated attackers to remotely modify or delete public projects and user data through a specific GraphQL directive. Self-managed administrators should update immediately to versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, as GitLab.com and Dedicated customers are already protected. No active exploitation or public exploit code was detected at the time of the release.