← All articles

Critical GitLab flaw lets unauthenticated attackers delete public projects and data

GitLab shipped an out-of-band critical patch for a flaw that lets an unauthenticated attacker remotely modify or delete public projects and user data through a GraphQL directive. Tracked as CVE-2026-19478 and scored 9.4, it affects self-managed Community and Enterprise installations; GitLab.com and Dedicated are already fixed. The company released it outside its normal twice-monthly schedule, and the fixed versions are 19.2.4, 19.1.6, 19.0.8, and 18.11.11, with the 18.2 through 18.10 branches left in the affected range and needing an upgrade. A second, lower-severity GraphQL flaw involving cross-site request forgery was fixed in the same release. GitLab reports no known exploitation yet.

Check
Upgrade self-managed GitLab to a fixed release immediately, and if you run a version between 18.2 and 18.10, plan an upgrade since those branches did not receive a backported fix.
Affected
Organizations running self-managed GitLab Community or Enterprise Edition (CVE-2026-19478); an unauthenticated attacker can remotely modify or delete public projects and user data through a GraphQL directive.
Fix
Apply the out-of-band patch now, prioritize internet-reachable instances, review logs for unexpected GraphQL activity and project or user changes, and restore any affected projects from backups if tampering is found.