Skip to content
Critical GitLab Vulnerability Allows Unauthenticated Data Deletion

Critical GitLab Vulnerability Allows Unauthenticated Data Deletion

First seen 18 Aug 2026, 09:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 19, 2026 at 07:37 UTC
  • •CVE-2026-19478 allows unauthenticated attackers to delete or modify public projects.
  • •GitLab's emergency patch was released on August 17, 2026, covering multiple affected versions.
  • •No confirmed exploitation has been reported, but immediate action is recommended for self-managed instances.

GitLab released an emergency patch on August 17, 2026, for a critical vulnerability tracked as CVE-2026-19478. This flaw allows unauthenticated attackers to remotely modify or delete public projects and user data through a GraphQL directive, with a CVSS score of 9.4. Affected versions include GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.2 to 19.2.4. Organizations using self-managed instances are urged to upgrade immediately, while GitLab.com and GitLab Dedicated are already patched. The vulnerability was reported via the HackerOne bug bounty program, and no public proof-of-concept code has been observed yet. A second vulnerability, CVE-2026-19650, a CSRF issue, was also patched in the same release. The lack of technical details may hinder detection of exploitation attempts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-04-22
CVE-2026-4922 published
GitLab patched a GraphQL CSRF flaw allowing unauthenticated mutations on behalf of users.
Techtimes
2026-07-29
CVE-2026-15975 published
GitLab released a patch for a denial-of-service flaw affecting merge request discussions.
docs.gitlab.com
2026-08-17
Emergency patch released for CVE-2026-19478
GitLab issued a critical patch for a vulnerability allowing unauthenticated data deletion and modification.
Techtimes
2026-08-18
First public PoC for CVE-2026-19478
Security researchers reported the ability to reproduce the vulnerability shortly after disclosure.
CSO Online
2026-08-18
CVE-2026-19650 also patched
A second vulnerability, a CSRF issue, was patched alongside CVE-2026-19478, affecting the same versions.
Darkreading

More articles in this cluster (30)

Following this threat?

Track CVE-2026-15975 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed