Cyber Resilience
← All news
Corroborated

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Our takeGitLab fixed CVE-2026-19478 (CVSS 9.4) that let unauthenticated attackers delete or modify public projects via GraphQL. It was exploited within hours of disclosure. Patch immediately if you self-host; hosted users are unaffected.
Sources (2)
What this means for you — Security leader:Update all self-hosted GitLab instances to 17.2.3, 17.1.5, 17.0.7 or later immediately. The unauthenticated GraphQL delete flaw (CVE-2026-19478) is already being exploited in the wild.
What this means for you — Lean IT orgs:If you self-host GitLab, update it today to the latest version. The flaw lets anyone delete your public projects without logging in and it is already being used.
What this means for you — MSP:Audit every client self-hosted GitLab instance and patch to 17.2.3/17.1.5/17.0.7+ as soon as possible; CVE-2026-19478 is under active exploitation.
What this means for you — Researcher:GitLab released fixes for CVE-2026-19478, a critical unauthenticated GraphQL mutation that can delete or modify public projects; exploitation observed within hours of disclosure.