Act
active
Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Delete Projects
- Engineer — Act: A public PoC on GitHub for a CVSS 9.4 unauthenticated flaw sharply raises exploitation risk even without KEV listing; patch GitLab CE/EE to the vendor’s latest patched release this week and verify no public GraphQL endpoints are exposed without authentication.
- SOC/IR — Act: With a public PoC already circulating, hunt for unauthenticated GraphQL mutation requests targeting GitLab’s project or user-data endpoints, and alert on anomalous project deletion or modification events since the vulnerability disclosure date.
- Leader — Plan: Confirm whether the organization runs self-hosted GitLab and ensure engineering has a same-week patching commitment; unauthorized source-code deletion or tampering carries supply-chain and business-continuity implications worth a brief status check with the team.
- Signals: CVE-2026-19478 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.