An unauthenticated GraphQL directive could delete public projects — GitLab shipped the fix off-schedule
2026-08-19Security
CVE-2026-19478 is a CVSS 9.4 in GitLab CE and EE: under certain conditions an unauthenticated user could modify or delete public projects and user data through a GraphQL directive. Patches landed on 17 August outside the normal release train. GitLab.com is already covered; self-hosted is not.