Critical GitLab Flaw Allows Unauthenticated Deletion of Public Projects
A critical vulnerability in GitLab CE/EE, CVE-2026-19478, allows unauthenticated attackers to delete or modify public projects and user data, with a CVSS score of 9.4.

GitLab has issued urgent security updates to address a critical vulnerability, CVE-2026-19478, that could permit unauthenticated attackers to remotely alter or delete public projects and associated user data. The flaw impacts both GitLab Community Edition (CE) and Enterprise Edition (EE) software, and has been assigned a Critical severity rating with a CVSS score of 9.4.
The out-of-band patch, released on August 17, 2026, arrived unexpectedly outside of GitLab's regular twice-monthly update schedule. This critical fix was deployed just five days after a routine patch release that did not contain any high-severity issues.
This vulnerability affects only self-managed GitLab installations. Users are urged to update to the patched versions, which include GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. GitLab has confirmed that GitLab.com and GitLab Dedicated environments are already running the patched versions, and customers using these services do not need to take any action.
The affected versions range from all versions starting from 18.2 up to, but not including, 18.11.11; versions 19.0 before 19.0.8; 19.1 before 19.1.6; and 19.2 before 19.2.4. Notably, versions 18.2 through 18.10, which fall within the affected range, do not have specific fixes extended to them beyond the general update.
GitLab's advisory states that the vulnerability could allow an unauthenticated user to remotely modify or delete public projects and user data through a specific GraphQL directive. The CVSS vector indicates that exploitation is possible over a network without requiring any credentials or user interaction from the victim. However, GitLab has not yet disclosed the specific GraphQL directive involved or the precise conditions required for exploitation.
As of August 18, 2026, GitLab has not reported any instances of this vulnerability being exploited in the wild, nor has any public exploit code surfaced on platforms like GitHub. This provides a window for administrators to apply the necessary patches before potential exploitation.
Alongside the critical flaw, the security update also addresses CVE-2026-19650, a High-severity vulnerability with a CVSS score of 7.1. This issue involves a cross-site request forgery (CSRF) weakness within the GraphQL multiplex query handler, which requires user interaction to be exploited. GitLab has remediated an issue where improper request validation in GraphQL multiplex query handling could allow an unauthenticated user to execute mutations via GET requests.
The company has stated that this update introduces no new migrations and is not expected to cause downtime for multi-node deployments. This disclosure follows a previous report in July 2026 detailing working exploit code for a separate GitLab vulnerability affecting self-managed servers. GitLab typically makes vulnerability details public on its issue tracker 90 days after a patch is released, meaning technical details for these flaws are expected around mid-November 2026.
This new report details an additional high-severity cross-site request forgery (CSRF) vulnerability, CVE-2026-19650, affecting GitLab's GraphQL multiplex query handler. This flaw could allow unauthenticated users to execute GraphQL mutations via GET requests if request validation is improperly handled, carrying a CVSS score of 7.1 and impacting the same GitLab version ranges as CVE-2026-19478.
The latest advisory from GitLab details two vulnerabilities, CVE-2026-19478 and CVE-2026-19650, impacting self-managed instances. While the prior report focused on the critical code injection flaw allowing data modification, this new information clarifies that the second vulnerability is a cross-site request forgery (CSRF) issue affecting GraphQL multiplex query handling, with a lower CVSS score of 7.1. Both flaws were reported via GitLab's HackerOne bug bounty program, and no in-the-wild exploitation has been reported for either.
This new report details a second vulnerability, CVE-2026-19650, a medium-severity cross-site request forgery (CVSS 7.1) affecting the GraphQL multiplex query handler. While exploitable by unauthenticated attackers, it requires user interaction and allows execution of mutations via GET requests, unlike the critical CVE-2026-19478 which allows direct modification or deletion of public projects without authentication.
This new report highlights that the primary challenge for organizations is the lack of detailed technical information surrounding CVE-2026-19478. This scarcity of data makes it difficult to develop effective detection mechanisms or confirm if self-managed GitLab instances have been compromised, despite the vulnerability's critical nature.
Researchers from watchTowr have confirmed that CVE-2026-19478, a critical GitLab code injection vulnerability, is actively being exploited in the wild. Their honeypot network detected exploitation attempts shortly after GitLab released patches for the flaw, which allows unauthenticated attackers to modify or delete public projects and forge merge records. The firm advises organizations to hunt for specific log entries and consider blocking unauthenticated GraphQL access if patching is delayed.
Just two days after the vulnerability was disclosed and patched, threat actors began actively exploiting CVE-2026-19478 in the wild. WatchTowr's honeypot network detected initial exploitation attempts, highlighting the narrow window for organizations to apply patches. The exploit allows unauthenticated attackers to delete public GitLab projects and rewrite their state, posing a significant risk to supply chain integrity by enabling the forging of trusted code reviews.
Preemptive exposure management firm watchTowr has confirmed that they were able to reproduce the vulnerability within minutes of its disclosure and have observed in-the-wild exploitation against their honeypot network. Researchers noted that the vulnerability's impact extends beyond modifying or deleting public projects, allowing attackers to delete entire repositories, forge merge records, and ban project maintainers. This rapid exploitation highlights the increasing speed of attacks, potentially accelerated by AI, making timely patching crucial.
The new article from Cyber Security News provides further details on the exploitation of CVE-2026-19478, noting that security firm WatchTowr reproduced the vulnerability and observed exploitation attempts in the wild shortly after disclosure. It also elaborates on the potential impact, including repository deletion and manipulation of merge records, and lists the specific affected and patched versions of GitLab CE/EE.