Threat Intelligence

Critical GitLab Flaw Could Let Hackers Delete Projects Without Logging In

The Hacker News · 18 Aug 2026
Key Takeaway If your business runs a self-hosted GitLab instance, update to the latest patched version immediately to prevent unauthenticated attackers from deleting your projects or data.

GitLab has issued security updates to fix a serious flaw in its Community Edition (CE) and Enterprise Edition (EE) software. The vulnerability, tracked as CVE-2026-19478, has been rated Critical with a CVSS score of 9.4, one of the highest severity ratings possible.

Under certain conditions, the flaw could allow an attacker with no login credentials at all to remotely modify or delete public GitLab projects and associated user data. For businesses using GitLab to store source code, manage development projects, or collaborate with teams, this represents a significant risk of data loss or disruption if left unpatched.

Any Australian small business running a self-hosted GitLab instance should treat this as an urgent update. GitLab-hosted (SaaS) customers are typically patched automatically, but self-managed installations require action from IT administrators.

GitLab Vulnerability Management Software Development Security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.