
GitLab Fixes Critical Flaw Allowing Unauthenticated Deletion of Public Projects
GitLab has issued an emergency out-of-band security update to fix a critical vulnerability that could allow unauthenticated attackers to remotely delete or alter public projects and user data. The patch, released on August 17, 2026, targets both the Community Edition (CE) and Enterprise Edition (EE) of the software, arriving just five days after a routine release that contained no critical fixes. The primary threat is tracked as CVE-2026-19478 and carries a near-maximum CVSS severity score of 9.4. According to GitLab, the flaw exists within a GraphQL directive. Because it can be exploited over a network without requiring attacker credentials or any interaction from a victim, the company categorized the threat as critical and pushed the release outside of its standard schedule of updates on the second and fourth Wednesdays of the month. A second high-severity flaw, CVE-2026-19650, was also addressed in the same update. Rated with a CVSS score of 7.1, this vulnerability involves a cross-site request forgery (CSRF) weakness in the GraphQL multiplex query handler. GitLab stated that improper validation could allow an unauthenticated user to execute mutations via GET requests, though this exploit requires user interaction to succeed. Currently, the danger is limited to self-managed servers. The company confirmed that its cloud-hosted services, GitLab.com and GitLab Dedicated, have already been updated and their users do not need to take any action. Administrators running their own installations, however, are urged to apply the patches immediately. The fixes have been rolled out in GitLab versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. The company warned that versions in the 18.2 through 18.10 branches fall within the affected range but will not receive patches. The update process is not expected to require downtime on multi-node deployments and introduces no new migrations. At the time of the release, GitLab noted no known active exploitation of either vulnerability. As of August 18, 2026, security researchers have not published any public exploit code on GitHub. However, the exact GraphQL directive involved and the specific conditions required for an attack remain undisclosed by the company. The security community will have to wait for technical specifics. Under a policy change enacted since a June 10, 2026 patch release—which extended the disclosure window from 30 days to 90 days—GitLab plans to make the vulnerability details public on its issue tracker around mid-November 2026. This approach aims to give administrators sufficient time to secure their systems before the methods become widely known. The urgent update arrives just weeks after a separate security incident. In July 2026, researchers publicly released working exploit code for a different GitLab flaw that also targeted self-managed servers, maintaining the pressure on organizations that host their own repositories. Technology companies and software development teams in Mogadishu and Hargeisa running their own GitLab instances to avoid high cloud hosting costs must manually apply these patches today to prevent their code repositories from being wiped out.
Read our sourcing and corrections policy



Be the first to comment on this story!