# GitLab patches critical unauthenticated GraphQL project-deletion flaw

_Monday, August 17, 2026 at 5:03 PM EDT · Security · Breaking · Tier 1 — Major_

![GitLab patches critical unauthenticated GraphQL project-deletion flaw — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLiZpsYdSdkh6GE1rDDV3XVwWiGdjWBlx3B1irY9V5RtHt1cv7sQYPaa16y78EJdluo3FTMr5Wq0O2ZCWZjRMdrewgLrGJS3Ii_NLOQKQKN18PEGHhDiSyJtvf8TpdFrrIplaynGWNVmUxdAkyL7E8h_GtKfog8EE_TV25SySHFqbQgK3ChyphenhyphenKaKktnUic/s1700-e365/gitlab.jpg)

GitLab released updates for a critical GraphQL vulnerability that could, under certain conditions, let an unauthenticated attacker remotely modify or delete public projects and user data on self-managed installations. GitLab rated CVE-2026-19478 at CVSS 9.4 and issued fixes in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. GitLab.com and GitLab Dedicated were already patched. The advisory does not name the affected directive or disclose the conditions required for exploitation.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html)

---
Canonical: https://techandbusiness.org/newswire/wh7jzciwpRzrTd_OwlF8UW
Retrieved: 2026-08-18T00:15:39.810Z
Publisher: Tech & Business (techandbusiness.org)
