securityaffairs.com 8/18/2026, 9:11:16 AM · external

GitLab Patches Critical Unauthenticated GraphQL Vulnerability

GitLab Patches Critical Unauthenticated GraphQL Vulnerability
Developing story vulnerability 4 articles tracked
GitLab GraphQL injection flaw (CVE-2026-19478) allows unauthenticated project modification
CyberSIXT Evidence Panel
Primary Source docs.gitlab.com
CISA KEV Not in KEV
Patch Patch Available

GITLAB has released an emergency patch for a critical unauthenticated GraphQL vulnerability (CVE-2026-19478) that allows remote modification or deletion of public projects on self-managed servers. The flaw has a CVSS score of 9.4 and affects versions prior to 19.2.4. Users must upgrade to avoid exploitation, especially those on unsupported older versions. Additionally, a less severe issue (CVE-2026-19650) was identified, which poses a lower risk due to requiring victim interaction.

As of now, there are no known exploits for either vulnerability, but organizations are advised to prioritize the patch due to the severity and nature of the issues.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline