TechNewsReel
Live

GitLab Patches Critical GraphQL Flaw Allowing Unauthenticated Project Deletion

A high-severity code injection vulnerability in self-managed GitLab instances could allow remote attackers to modify or delete public data.

TechNewsReel Newsroom · August 17, 2026

GitLab released critical security updates on August 17, 2026, to resolve a severe code injection vulnerability within its GraphQL directive. The flaw allows unauthenticated attackers to remotely modify or delete public projects and user data under specific conditions.

Tracked as CVE-2026-19478 with a CVSS score of 9.4, the vulnerability impacts both Community Edition (CE) and Enterprise Edition (EE) self-managed installations. Specifically, affected versions include GitLab CE/EE from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

Discovery and Patching

Security researcher hiimguardian identified and reported the vulnerability through GitLab's HackerOne bug bounty program. In response, GitLab issued a series of ad-hoc critical patch releases to neutralize the threat. This update was deployed alongside a fix for a separate high-severity cross-site request forgery (CSRF) issue, tracked as CVE-2026-19650.

Industry Implications

Because the vulnerability is exploitable by users without authentication, it presents a significant risk to the integrity and availability of open-source projects and user data. For organizations hosting their own GitLab infrastructure, the ability for an external actor to delete or alter public projects could lead to permanent data loss or the injection of malicious code into public repositories.

While GitLab.com and GitLab Dedicated environments were patched automatically by the provider, the risk remains high for the thousands of self-managed servers globally. These installations require manual updates to the patched versions to close the security gap.

Next Steps for Administrators

System administrators are urged to verify their current GitLab version and apply the necessary updates immediately. The critical patches are available for versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4. Organizations should prioritize these updates to prevent unauthorized remote access to their project data. Failure to update leaves the infrastructure vulnerable to remote actors who can bypass authentication to manipulate public-facing repositories, potentially compromising the software supply chain for any downstream users relying on those projects.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.