Security BREAKING
GitLab patches critical unauthenticated GraphQL project-deletion flaw
Image: Primary GitLab released updates for a critical GraphQL vulnerability that could, under certain conditions, let an unauthenticated attacker remotely modify or delete public projects and user data on self-managed installations. GitLab rated CVE-2026-19478 at CVSS 9.4 and issued fixes in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. GitLab.com and GitLab Dedicated were already patched. The advisory does not name the affected directive or disclose the conditions required for exploitation.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire