Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

August 24, 2026

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

August 24, 2026

Researchers Uncover Thousands of Leaked AWS Keys

August 24, 2026
Facebook X (Twitter) Instagram
Monday, August 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
News

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Team-CWDBy Team-CWDAugust 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.

The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4.

Released on August 17, 2026, the critical patch release arrived outside the company’s usual schedule of twice-monthly updates on the second and fourth Wednesdays, five days after a routine patch release that carried no critical-rated issues.

Only self-managed installations need to act. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

“GitLab.com and GitLab Dedicated are already running the patched version. GitLab.com and GitLab Dedicated customers do not need to take action,” the company said.

The following versions are affected –

  • All versions from 18.2 before 18.11.11
  • 19.0 before 19.0.8
  • 19.1 before 19.1.6
  • 19.2 before 19.2.4

The fixes do not extend to the 18.2 through 18.10 branches, which fall inside the affected range.

“GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive,” GitLab said.

The CVSS vector published for the flaw indicates that it can be exploited over a network by an attacker holding no credentials, and without any action on the part of a victim.

GitLab has not named the GraphQL directive involved or specified what the conditions necessary for exploitation are.

The advisory discloses no exploitation of either flaw, and no public exploit code for them has surfaced on GitHub as of August 18, 2026.

The second issue fixed in the release, CVE-2026-19650, has been rated High by GitLab with a CVSS score of 7.1, and concerns a cross-site request forgery (CSRF) weakness in the GraphQL multiplex query handler.

Unlike the critical flaw, it requires user interaction to work.

“GitLab has remediated an issue that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling,” the company said.

The company said the update introduces no new migrations and is not expected to require downtime on multi-node deployments.

The disclosure follows a July 2026 report in which researchers published working exploit code for a separate GitLab flaw affecting self-managed servers.

GitLab did not immediately respond to a request for comment.

The company said it makes the issues detailing each vulnerability public on its issue tracker 90 days after the release that patched them. GitLab’s June 10, 2026 patch release put that window at 30 days.

That places technical details of both flaws at around mid-November 2026.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSnowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Next Article CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Team-CWD
  • Website

Related Posts

News

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

August 24, 2026
News

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

August 24, 2026
News

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

August 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

Why you should never pay to get paid

September 15, 2025

How it preys on personal data – and how to stay safe

October 23, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.