GitLab ships an emergency fix for CVE-2026-19478: unauthenticated delete of public projects
GitLab's out-of-band release patches CVE-2026-19478, CVSS 9.4, which lets an unauthenticated user modify or delete public projects and user data via a GraphQL directive. Fixed in 18.11.11, 19.0.8, 19.1.6 and 19.2.4. Self-managed only. It is not a remote code execution bug.

GitLab shipped an ad hoc critical patch release on 17 August 2026, outside its normal schedule, for CVE-2026-19478, rated CVSS 9.4. In its own advisory, GitLab says the issue "under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive."
The patched builds are 18.11.11, 19.0.8, 19.1.6, and 19.2.4. Affected versions are every build from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
The affected window opens at 18.2, but the published fixes only cover the 18.11, 19.0, 19.1, and 19.2 branches. Installations on 18.2 through 18.10 have no in-branch patch. Those operators cannot apply a point release and stay where they are. They have to upgrade to a supported release.
GitLab.com and GitLab Dedicated are already running the patched version, and GitLab states those customers do not need to take action. The exposure is self-managed GitLab only.
The vulnerability class is code injection, and a lot of write-ups slid from there to language about attackers running their own instructions on the server. GitLab did not say that, and the CVSS vector rules it out. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H.
The part to notice is C:L. Confidentiality impact is rated Low. Integrity and availability are both High. The 9.4 is driven by what an attacker can destroy and alter, not by what they can read or execute.
That means unauthenticated modify and delete against public projects and user data. GitLab did not describe a path to dumping private repositories or a shell on the box.
The same release also fixes CVE-2026-19650, a cross-site request forgery issue in the GraphQL multiplex query handler, rated CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L). The UI:R mark means that one needs a logged-in user to be lured into clicking, which is why it is the lesser of the two.
Both came in through HackerOne. GitLab credits hiimguardian for the critical GraphQL directive issue and kreep for the CSRF.
No public proof-of-concept code had surfaced for either issue at the time of writing, and neither appears in CISA's Known Exploited Vulnerabilities catalog. An unauthenticated, no-user-interaction bug on an internet-reachable GraphQL endpoint is the profile that gets swept up in mass scanning once someone publishes a proof of concept, and GitLab breaking its own release schedule is how it rated the risk. GitLab "strongly recommends" affected installations upgrade "as soon as possible."
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free