Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
- Posted on August 17, 2026
- By The Hacker News
- 1 Views
- 1 min read
GitLab has addressed a severe security vulnerability in its GraphQL API that exposed public projects to unauthorized manipulation. Tracked as CVE-2026-19478 with a critical CVSS score of 9.4, this flaw allowed unauthenticated attackers to modify or completely remove project and user data without proper authentication. The discovery highlights the importance of securing API endpoints and implementing robust access controls in development platforms.
Summary auto-generated by AI from the original publisher's content. Editorial standards.