⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Critical GitLab GraphQL Flaw CVE-2026-19478 Allows Unauthenticated Project Deletion

August 17, 2026

GitLab has released emergency security updates to address a critical vulnerability in its Community Edition (CE) and Enterprise Edition (EE) that could allow unauthenticated attackers to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, carries a CVSS score of 9.4 and affects self-managed installations only. GitLab.com and GitLab Dedicated are already patched.

The vulnerability resides in a GraphQL directive and can be exploited over the network without credentials or user interaction. GitLab has not disclosed the specific directive or exploitation conditions. The patch is available in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. Versions 18.2 through 18.10 remain affected and are not covered by the fix.

A second issue, CVE-2026-19650, rated High with a CVSS score of 7.1, fixes a CSRF weakness in the GraphQL multiplex query handler that could allow unauthenticated mutation execution via GET requests. This flaw requires user interaction.

GitLab released the patch on August 17, 2026, outside its regular schedule, and stated that no new migrations are required and multi-node deployments should not experience downtime. Technical details are expected to be published on GitLab’s issue tracker around mid-November 2026.

CVEs: CVE-2026-19478, CVE-2026-19650

Companies: GitLab

Products: GitLab Community Edition, GitLab Enterprise Edition, GitLab.com, GitLab Dedicated