CVE-2026-19478 GitLab GraphQL unauthenticated project deletion
github.com | vulnerability | Critical | CVE-2026-19478 | #gitlab | #access-control | #authentication | #vulnerability | #cve | #graphql | #project-deletion | #poc | #unauthenticated | #cve-2026-19478
Summary
EQSTLab's PoC for CVE-2026-19478 (CVSS 9.4): GitLab's @gl_introduced fallback resolves arbitrary zero-arg methods — unauthenticated 'destroy' queries delete public projects; fixed in 18.11.11/19.2.4.
Why it matters
This vulnerability allows remote unauthenticated actors to delete projects in vulnerable GitLab instances, necessitating immediate patching.
- Vendor
- GitLab
- Product
- GitLab CE/EE
- Affected versions
- 18.2–18.11.10, 19.0.0–19.0.7, 19.1.0–19.1.5, 19.2.0–19.2.3
- CVSS
- 9.1
- Published
- Collected
Skip to content