← Back

Wire · technology

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Published

17 August 2026

Topic

technology

◆ Sectors

Enterprise SoftwareSecurity Infrastructure

◆ Source

Read at thehackernews.com →

◆ Verified

Fusion42 · 18 August 2026 · Fusion42 review

GitLab patched a critical CVE-2026-19478 vulnerability with a 9.4 CVSS score affecting Community and Enterprise Edition self-managed installations. The flaw allowed unauthenticated attackers to remotely delete or modify public projects and data via a GraphQL directive, requiring urgent updates on certain versions.

This Wire brief sits within Fusion42's coverage of Enterprise Software and Security Infrastructure, and 4 sources have reported it between 17 Aug 2026 and 21 Aug 2026.

◆ ◆ The Wire takeaway

The critical GitLab flaw exposes a severe risk to self-hosted GitLab users, forcing you to prioritise immediate patching or face permanent data loss and service disruption. Your DevOps security now demands urgent review of GraphQL endpoint protections.

◆ Coverage

4 sources · first reported 17 Aug 2026 · latest 21 Aug 2026

◆ Related on Wire

◆ Topics

Enterprise SoftwareSecurity Infrastructuregitlabgraphqlsecurity-flawpatchunauthenticated-accessopensource