Tuttiquotidiani is completely free. Every day we aggregate news from 100+ sources and generate original AI summaries for you. Help us keep the service running with a small donation, or become TQ Pro for just €1/month.

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

  • Posted on August 17, 2026
  • By The Hacker News
  • 1 Views
  • 1 min read
In brief

GitLab has addressed a severe security vulnerability in its GraphQL API that exposed public projects to unauthorized manipulation. Tracked as CVE-2026-19478 with a critical CVSS score of 9.4, this flaw allowed unauthenticated attackers to modify or completely remove project and user data without proper authentication. The discovery highlights the importance of securing API endpoints and implementing robust access controls in development platforms.

Summary auto-generated by AI from the original publisher's content. Editorial standards.

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab patches CVE-2026-19478, a CVSS 9.4 GraphQL flaw that could let unauthenticated attackers modify or delete public project and user data
continue reading...

Author
The Hacker News

You May Also Like