Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Read original article ↗AI Summary
GitLab has patched a critical vulnerability, CVE-2026-19478, affecting its self-managed Community and Enterprise Editions, which could allow unauthenticated attackers to remotely modify or delete public projects and user data under certain conditions. The flaw exists in the GraphQL implementation and can be exploited over the network without authentication or user interaction. The vulnerability impacts versions 18.2 to 18.11.10, 19.0 to 19.0.7, 19.1 to 19.1.5, and 19.2 to 19.2.3. A second high-severity issue, CVE-2026-19650, was also fixed, involving a CSRF vulnerability in the GraphQL multiplex query handler that allows unauthenticated mutation execution via GET requests under certain conditions.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.