CVE Tools
Back to feed
Patch released GitLab CE web-app GitLab EE GitLab rce

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

GitLab has issued an out-of-cycle security patch for Community Edition and Enterprise Edition to fix critical vulnerability CVE-2026-19478. Rated 9.4 by the vendor, this flaw allows unauthenticated attackers to remotely modify or delete public projects and user data through a specific GraphQL directive. Self-managed administrators should update immediately to versions 19.2.4, 19.1.6, 19.0.8, or 18.11.11, as GitLab.com and Dedicated customers are already protected. No active exploitation or public exploit code was detected at the time of the release.