# Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Wipe Public Projects
## The Threat
GitLab's GraphQL API has a serious authorization problem, and it requires zero authentication to exploit. The vulnerability, tracked as CVE-2026-19478, allows an unauthenticated remote attacker to modify or delete public projects and associated user data on affected GitLab instances — no login, no session token, no foothold required.
GraphQL authorization flaws are particularly insidious because they tend to hide behind the appearance of proper access controls. Unlike REST APIs where endpoints map cleanly to permission checks, GraphQL's flexible query model creates surface area where object-level authorization can be inconsistently applied — or skipped entirely. In this case, GitLab's GraphQL layer apparently failed to enforce ownership or session checks before processing destructive mutations against public project resources.
The damage potential here is hard to overstate for organizations running self-managed GitLab instances. Public projects aren't just open-source curiosities — many organizations use GitLab's visibility tiers to expose project documentation, package registries, or CI/CD artifacts to external partners. Any of those projects are in scope for an unauthenticated attacker who finds this endpoint.
## Severity and Impact
| Field | Details |
|---|---|
| CVE | CVE-2026-19478 |
| CVSS Score | 9.4 (Critical) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Complexity | Low |
| Authentication Required | None |
| CWE | CWE-285: Improper Authorization |
| Attack Vector | Network (Remote) |
| Impact | Unauthorized modification and deletion of public projects and user data |
## Affected Products
Both major GitLab distribution channels are affected:
GitLab.com (the SaaS platform) has been patched by GitLab's security team and requires no customer action. The risk exposure falls almost entirely on self-managed deployments.
## Mitigations
Apply the security update immediately. GitLab has released patched versions for both CE and EE. Self-managed administrators should upgrade without waiting for a scheduled maintenance window given the critical severity and zero-authentication requirement.
If an immediate upgrade is not possible, the following controls reduce the attack surface:
/api/graphql) via your reverse proxy or firewall until patching is complete.projectDelete, projectUpdate, or similar events executed without authenticated sessions.For GitLab.com users: no action required. GitLab has already deployed the fix to its managed infrastructure.
## References
---
## HackWire Analysis
A CVSS 9.4 with no authentication requirement is the kind of score that should send your on-call rotation scrambling on a Sunday night — and yet self-managed GitLab administrators are disproportionately likely to be under-resourced compared to their GitLab.com counterparts who get this patched automatically. That asymmetry is where the real risk lives.
GitLab is used extensively by government agencies, defense contractors, financial services firms, and critical infrastructure operators who have compliance or data residency reasons to self-host. Those are exactly the environments where "public project" is a deliberate configuration — internal wikis, shared pipeline templates, open tooling repos — and where unauthorized deletion of source code or CI/CD infrastructure could cascade into service disruptions far beyond a single repository.
The GraphQL angle is worth watching as a trend. Over the past two years, GraphQL authorization bypass vulnerabilities have appeared in Shopify, GitHub Enterprise, HackerOne, and now GitLab — suggesting that the security tooling and review practices for GraphQL APIs remain immature compared to REST endpoints. The attack surface is wider, introspection can leak schema details to attackers, and batching requests makes rate-limiting harder. Most organizations still don't treat their GraphQL layer with the same skepticism they'd apply to a public REST API.
The specific combination of unauthenticated access plus write/delete operations — not just data leakage — makes this different from the average disclosure. Attackers don't need to exfiltrate anything to cause significant damage. Ransomware groups and state-sponsored actors targeting developer infrastructure have demonstrated appetite for exactly this kind of destructive capability. Patch now; audit your public project inventory while you wait for the package to download.
— HackWire Editorial
---
## Related Coverage