discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user…

By Swati Khandelwal·Aug 17·thehackernews.com·2 min read

Intelligence analysis by Llama

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Image: thehackernews.com

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4.

Why it matters

This story matters to someone following Security because it highlights a critical vulnerability in GitLab's Community Edition (CE) and Enterprise Edition (EE) software that could allow an unauthenticated attacker to remotely modify or delete public projects and user data.

Imagine you have a public project on a website where you can share your work with others. But, there's a bug in the website's code that allows someone to delete your project without needing a password. This is what happened with GitLab, a website where developers share their projects. A bug in their code allowed someone to delete public projects and user data without needing a password.

Analysis

Vulnerability Details

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. The vulnerability could allow an unauthenticated attacker to remotely modify or delete public projects and user data via a GraphQL directive.

Affected Versions

The following versions are affected:

  • All versions from 18.2 before 18.11.11
  • 19.0 before 19.0.8
  • 19.1 before 19.1.6
  • 19.2 before 19.2.4

Fixes

The fixes do not extend to the 18.2 through 18.10 branches, which fall inside the affected range. GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Second Issue Fixed

The second issue fixed in the release, CVE-2026-19650, has been rated High by GitLab with a CVSS score of 7.1, and concerns a cross-site request forgery (CSRF) weakness in the GraphQL multiplex query handler. Unlike the critical flaw, it requires user interaction to work.

Key points

  • GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software.
  • The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4.
  • The vulnerability could allow an unauthenticated attacker to remotely modify or delete public projects and user data via a GraphQL directive.
  • The fixes do not extend to the 18.2 through 18.10 branches, which fall inside the affected range.
  • The second issue fixed in the release, CVE-2026-19650, has been rated High by GitLab with a CVSS score of 7.1, and concerns a cross-site request forgery (CSRF) weakness in the GraphQL multiplex query handler.
The Upside

If the vulnerability is patched quickly, it's possible that the impact will be minimal, and users will not lose any data. Additionally, the fact that GitLab has released security updates to address the issue shows that they are taking the problem seriously and are working to fix it.

The Downside

The fact that the vulnerability was not discovered until now means that it could have been exploited for a long time, potentially leading to significant data loss or other security issues. Additionally, the fact that the second issue fixed in the release, CVE-2026-19650, requires user interaction to work means that users may have been vulnerable to this issue as well.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentscybersecuritydevopsgitlabgraphqlsecurityvulnerability

Author

Swati Khandelwal

Intelligence analysis by

Llama

Published

Aug 17, 2026

Source

thehackernews.com

Share

Topics

ai-agentscybersecuritydevopsgitlabgraphqlsecurityvulnerability

Related

More from this desk

Aug 17·bleepingcomputer.com

Hacker claims 3.6 million Azure account records stolen from major companies

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.

Aug 17·bleepingcomputer.com

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center has suffered a data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. The exposed records belonged to Pokémon Center customers who submitted orders on the site. The company has canceled so…

Aug 17·bleepingcomputer.com

Microsoft Confirms GitHub is Down Worldwide

GitHub is experiencing a widespread outage, causing errors across the website, API, Actions, Pull Requests, and other services. Microsoft confirmed the outage and is investigating the cause.

Aug 17·bleepingcomputer.com

Certighost and the Privilege Hiding in Your Certificate Authority

A vulnerability in the Certification Authority (CA) in Active Directory environments allows a low-privileged user to obtain a valid authentication certificate for a Domain Controller, which can be used to become the Domain Controller. This is a trust-validation problem th…