Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical GitLab Flaw Could Let Attackers Change or Delete Your Public Projects

A serious security flaw has been found in GitLab, a popular tool used to manage software projects. This flaw could allow someone without permission to change or delete public projects and user data. It is important for organisations using GitLab to check and update their software to prevent potential attacks.

19 August 2026

Reference: CVE-2026-19478

1. What is being reported?

The report describes a critical security issue in certain versions of GitLab. Under specific conditions, an attacker who is not logged in could use a feature called GraphQL to remotely modify or delete public projects and user data.

2. What this means in plain English

If your organisation uses GitLab to manage projects or code, this flaw could let an attacker disrupt your work by deleting or changing important information without needing a password. This could cause loss of data and interrupt your operations.

3. Could this affect a small business?

Small businesses or charities using affected versions of GitLab, especially if they have public projects, could be at risk. If you do not use GitLab or only use private projects, the risk is likely lower. Ask your IT provider if you are unsure.

4. What to do now

  • Check if your organisation uses GitLab and identify the version in use.
  • If using an affected version, update GitLab immediately to the latest fixed version.
  • Review your public projects and back up important data regularly.
  • Ask your IT provider to confirm that your GitLab installation is secure and up to date.

5. Ask your IT provider

Can you confirm whether our GitLab installation is affected by CVE-2026-19478 and if it has been updated to a safe version?

6. Bottom line

Keep your GitLab software updated to protect your projects from unauthorised changes or deletion.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs