CRITICAL 9.4 CVE-2026-19478 Published 17 Aug 2026

GitLab CE/EE GraphQL Directive Flaw Lets Unauthenticated Users Modify or Delete Data

Worried this affects your website?

GitLab CE/EE has released fixes for an unauthenticated data modification and deletion vulnerability. Under certain conditions, a remote attacker with no authentication could modify or delete public projects and user data via a GraphQL directive.

Affected versions:

  • 18.2 before 18.11.11
  • 19.0 before 19.0.8
  • 19.1 before 19.1.6
  • 19.2 before 19.2.4

GitLab has remediated the issue in the latest releases.

Reference: CVE-2026-19478 on NVD

← Back to Security News