Self-hosted GitLab servers need an urgent update. Public projects could be changed or deleted
A critical GraphQL flaw can be exploited without signing in. GitLab.com is already patched.
SOURCE · SecurityWeekGitLab has fixed a critical GraphQL weakness that could allow an unauthenticated attacker to modify or delete user data and public projects. The absence of a login requirement is what raises the risk: an exposed self-managed server could be targeted without stolen credentials or an existing foothold. Public repositories may contain source code, issue history and project records that development teams depend on, so destructive changes could disrupt work even when confidential code is not exposed. The flaw, CVE-2026-19478, affects several recent Community and Enterprise Edition release lines. GitLab.com and GitLab Dedicated are already patched; organizations running GitLab themselves must upgrade to 18.11.11, 19.0.8, 19.1.6, 19.2.4 or a later release. After updating, review audit events, unexpected project changes and deletion activity. A successful upgrade closes the vulnerability, but it does not prove the server was untouched beforehand.
SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.
