By Interestana AI Editorial — AI-drafted, human-overseen. How we report
GitLab Critical Flaw Allows Unauthenticated Project Deletion

GitLab has issued security updates to address a critical vulnerability affecting its Community Edition (CE) and Enterprise Edition (EE) software. This flaw, identified as CVE-2026-19478, carries a CVSS score of 9.4 and has been classified as Critical by GitLab. The vulnerability, if exploited under specific conditions, could permit an unauthenticated attacker to remotely alter or delete public projects and associated user data. The company disclosed the vulnerability and its associated patches on January 15, 2026, urging users to apply the updates promptly to mitigate potential risks. The affected versions include GitLab CE/EE versions prior to 17.4.1, 17.3.4, and 17.2.6. The vulnerability stems from an issue within the GraphQL API, specifically related to how certain project deletion mutations were handled. An attacker could leverage this by sending a specially crafted GraphQL request to the GitLab instance. This request would bypass authentication checks and trigger the deletion of a public project, including all its associated data, such as repositories, issues, merge requests, and user comments. The potential impact is significant, as it could lead to irreversible data loss and disruption of services for projects hosted on vulnerable GitLab instances. GitLab's advisory emphasizes that while the vulnerability requires specific conditions to be met, the severity of its potential impact warrants immediate attention. The company has provided detailed instructions on how to update the software to the patched versions. Users are advised to consult the official GitLab security release notes for comprehensive information on the vulnerability and the steps required for remediation. The fix involves strengthening the authorization checks within the GraphQL API to ensure that only authenticated and authorized users can perform sensitive operations like project deletion. This incident underscores the ongoing challenges in securing complex software platforms like GitLab, which are widely used for code hosting and collaboration by organizations worldwide. The prompt release of patches and clear communication from GitLab are crucial steps in managing the fallout from such critical security disclosures. The company has also indicated that it is conducting an internal review to prevent similar vulnerabilities from arising in the future. The vulnerability was discovered by an independent security researcher, whose identity has not been disclosed by GitLab in the initial advisory. The researcher's findings were responsibly reported to GitLab, allowing the company sufficient time to develop and test a fix before public disclosure. This collaborative approach between security researchers and software vendors is vital for maintaining a secure digital ecosystem. The implications of this vulnerability extend to any organization using GitLab for managing public-facing projects, including open-source software development, public documentation repositories, and community forums. The ability for an unauthenticated attacker to delete such projects could have severe reputational and operational consequences. GitLab's commitment to addressing this issue swiftly demonstrates its dedication to user security and data integrity. The company's proactive stance in releasing patches and providing clear guidance aims to minimize the window of opportunity for exploitation. The security updates are available for download from GitLab's official website and are recommended for all users of affected versions. The company continues to monitor for any signs of exploitation and is working with the security community to stay ahead of emerging threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.