Ethical Hacking News
GitLab has released an emergency patch to address a critical unauthenticated GraphQL vulnerability, leaving self-managed server users vulnerable to remote modification or deletion of public projects and user data. Users are advised to upgrade to the latest patched versions to protect themselves against this vulnerability.
GitLab has released an emergency patch to address a critical GraphQL vulnerability (CVE-2026-19478) with a CVSS score of 9.4.The vulnerability allows an attacker with zero credentials to remotely modify or delete public projects and user data via a GraphQL directive.Only self-managed installations are impacted, and users are advised to upgrade to versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.There is a gap in available patches for versions 18.2-18.10, requiring users to upgrade to a patched branch entirely.A second, less severe issue (CVE-2026-19650) involves a cross-site request forgery weakness in GraphQL multiplex queries.No evidence of exploitation in the wild, but full technical details will be publicly available in mid-November.Organizations running GitLab on self-managed servers should prioritize addressing this vulnerability.
GitLab has recently released an emergency patch to address a critical flaw in its GraphQL system, which has left self-managed server users vulnerable to remote modification or deletion of public projects and user data. The vulnerability, tracked as CVE-2026-19478, has a CVSS score of 9.4, making it a serious security threat. According to the advisory issued by GitLab, the vulnerability could allow an attacker with zero credentials to remotely modify or delete public projects and user data via a GraphQL directive.
The patch, which was released on August 17, impacts only self-managed installations, and users are advised to upgrade to versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. However, there is a gap in the available patches, as versions 18.2 through 18.10 are not covered, even though they technically fall within the affected range. This means that users running these older releases will need to upgrade to a patched branch entirely, rather than waiting for a fix that is not currently available.
The vulnerability was reported by hiimguardian through the company's HackerOne bug bounty program. A second, less severe issue, CVE-2026-19650, involves a cross-site request forgery weakness in how GitLab's GraphQL handles multiplex queries, allowing an unauthenticated attacker to trigger mutations through GET requests due to improper validation. While this vulnerability is less severe, it still poses a risk and should be addressed by users.
It's worth noting that there is currently no evidence that the bug has been exploited in the wild, and no public proof-of-concept code has surfaced as of publication. However, GitLab's own disclosure policy means that full technical details of the vulnerability will be publicly available 90 days after the patching release, which puts a working understanding of exactly how the bug functions in mid-November. This means that users who are motivated enough to reverse-engineer the patch diff will have plenty of time to exploit the vulnerability before then.
The critical nature of this vulnerability, combined with the fact that it requires no authentication or user interaction, makes it a serious threat to self-managed server users. Organizations running GitLab on their own infrastructure should therefore treat this patch as a priority. The recent release of working exploit code for another remote-code-execution flaw affecting self-managed servers further emphasizes the importance of addressing this vulnerability.
In conclusion, the critical unauthenticated GraphQL vulnerability in GitLab highlights the need for self-managed server users to stay up-to-date with the latest security patches. The vulnerability's severity, combined with the fact that it can be exploited without user interaction, makes it a serious threat that should not be taken lightly. Users are advised to upgrade to the latest patched versions as soon as possible to protect themselves against this vulnerability.
GitLab has released an emergency patch to address a critical unauthenticated GraphQL vulnerability, leaving self-managed server users vulnerable to remote modification or deletion of public projects and user data. Users are advised to upgrade to the latest patched versions to protect themselves against this vulnerability.
Related Information:
https://www.ethicalhackingnews.com/articles/GitLab-Patches-Critical-Unauthenticated-GraphQL-Vulnerability-Leaving-Self-Managed-Server-Users-Vulnerable-ehn.shtml
https://securityaffairs.com/197454/hacking/gitlab-patches-critical-unauthenticated-graphql-vulnerability.html
https://nvd.nist.gov/vuln/detail/CVE-2026-19478
https://www.cvedetails.com/cve/CVE-2026-19478/
https://nvd.nist.gov/vuln/detail/CVE-2026-19650
https://www.cvedetails.com/cve/CVE-2026-19650/
Published: Tue Aug 18 05:08:06 2026 by llama3.2 3B Q4_K_M