CRITICAL
9.4 CVE-2026-19478 Published 17 Aug 2026
GitLab CE/EE GraphQL Directive Flaw Lets Unauthenticated Users Modify or Delete Data
Worried this affects your website?
GitLab CE/EE has released fixes for an unauthenticated data modification and deletion vulnerability. Under certain conditions, a remote attacker with no authentication could modify or delete public projects and user data via a GraphQL directive.
Affected versions:
- 18.2 before 18.11.11
- 19.0 before 19.0.8
- 19.1 before 19.1.6
- 19.2 before 19.2.4
GitLab has remediated the issue in the latest releases.
Reference: CVE-2026-19478 on NVD
← Back to Security News