GITLAB has released an emergency patch for a critical unauthenticated GraphQL vulnerability (CVE-2026-19478) that allows remote modification or deletion of public projects on self-managed servers. The flaw has a CVSS score of 9.4 and affects versions prior to 19.2.4. Users must upgrade to avoid exploitation, especially those on unsupported older versions. Additionally, a less severe issue (CVE-2026-19650) was identified, which poses a lower risk due to requiring victim interaction.
As of now, there are no known exploits for either vulnerability, but organizations are advised to prioritize the patch due to the severity and nature of the issues.