As cited
Copy frozen at (site build).
vulnerabilities
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab released security updates for a critical GraphQL vulnerability tracked as CVE-2026-19478 that could allow unauthenticated attackers to modify or delete public projects and user data in Community and Enterprise editions. The flaw carries a CVSS score of 9.4. The article text is incomplete.
Why it matters: Organizations running GitLab CE or EE must apply updates immediately to prevent unauthorized deletion or modification of public repositories and user data by unauthenticated actors.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab released security updates for a critical GraphQL vulnerability tracked as CVE-2026-19478 that could allow unauthenticated attackers to modify or delete public projects and user data in Community and Enterprise editions. The flaw carries a CVSS score of 9.4. The article text is incomplete.
Why it matters: Organizations running GitLab CE or EE must apply updates immediately to prevent unauthorized deletion or modification of public repositories and user data by unauthenticated actors.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab released security updates for a critical GraphQL vulnerability tracked as CVE-2026-19478 that could allow unauthenticated attackers to modify or delete public projects and user data in Community and Enterprise editions. The flaw carries a CVSS score of 9.4. The article text is incomplete.
Why it matters: Organizations running GitLab CE or EE must apply updates immediately to prevent unauthorized deletion or modification of public repositories and user data by unauthenticated actors.
- Source published
- First seen by Cybersecurity Tracker