CuraSec

Act active

Critical GitLab GraphQL Flaw Lets Unauthenticated Attackers Delete Projects

2026-08-18 11:37 UTC · The Hacker News · read the source ↗ #gitlab#graphql#critical-vulnerability
  • Engineer — Act: A public PoC on GitHub for a CVSS 9.4 unauthenticated flaw sharply raises exploitation risk even without KEV listing; patch GitLab CE/EE to the vendor’s latest patched release this week and verify no public GraphQL endpoints are exposed without authentication.
  • SOC/IR — Act: With a public PoC already circulating, hunt for unauthenticated GraphQL mutation requests targeting GitLab’s project or user-data endpoints, and alert on anomalous project deletion or modification events since the vulnerability disclosure date.
  • Leader — Plan: Confirm whether the organization runs self-hosted GitLab and ensure engineering has a same-week patching commitment; unauthorized source-code deletion or tampering carries supply-chain and business-continuity implications worth a brief status check with the team.
  • Signals: CVE-2026-19478 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.