Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Summary
GitLab has released security updates for critical vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE) software. A flaw, tracked as CVE-2026-19478, could allow unauthenticated attackers to remotely modify or delete public projects and user data.
IFF Assessment
FOE
This vulnerability allows unauthenticated attackers to delete public projects and user data, which is a direct threat to defenders' assets and information.
Severity
9.4
Critical
Defender Context
This critical vulnerability in GitLab allows unauthenticated attackers to delete public projects, posing a significant risk to code repositories and associated data. Defenders should prioritize patching affected GitLab instances immediately to prevent unauthorized data deletion and potential project compromise.