#3
The Hacker News
general
August 17, 2026 at 21:03 UTC
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
By [email protected] (The Hacker News)
AI Summary
GitLab patched CVE-2026-19478 (CVSS 9.4), a critical GraphQL flaw in both Community and Enterprise Editions that allows unauthenticated attackers to remotely modify or delete public projects and user data. Organizations running self-managed GitLab instances should apply the security update immediately given the unauthenticated attack surface.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →