Database/Control plane, storage & DevOps
GitLab: an unauthenticated GraphQL directive can modify or delete public projects and user data
Impact
Under conditions GitLab does not detail, an unauthenticated request using a GraphQL directive modifies or deletes public projects and user data. On a self-hosted GitLab that is the system of record for pipeline definitions, infrastructure-as-code, and container build recipes for the fleet, so this is both a data-destruction event and a path to tampering with what CI runners execute on GPU nodes. Integrity and availability are rated high while confidentiality is only low, so the realistic outcome is destruction and modification rather than mass data theft. Affected: 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
Who can reach it
Anyone who can reach the GitLab web endpoint. No authentication, no user interaction. Internet-facing instances are exposed directly; internal-only instances are exposed to anyone on the corporate or management network.
What to do
Upgrade to 18.11.11, 19.0.8, 19.1.6, or 19.2.4 as matches your branch. This is a control-plane package upgrade and service restart (for Omnibus, reconfigure and restart), costing a short GitLab outage — no node drain, no impact on running GPU jobs, though queued pipelines will pause for the duration.
References
Related entries
- CloudNativePG: a database owner escalates to PostgreSQL superuser and OS command execution in the podCVE-2026-55769 · CloudNativePG instance manager (unpinned search_path on superuser connections)Critical
- CloudNativePG instance manager (PostgreSQL connection search_path): The owner of any managed database — a roleNCVD-2026-048-cloudnativepg-instance-manager-p · CloudNativePG instance manager (PostgreSQL connection search_path)Critical
- Pure Storage FlashBlade management interface authentication: An attacker authenticates to the FlashBlade managementCVE-2023-4976 · Pure Storage FlashBlade management interface authenticationCritical
- MinIO (admin IAM import API): The IAM import API can be driven to grant an attacker administrative policy, converting aCVE-2024-55949 · MinIO (admin IAM import API)Critical
- Renovate: shell metacharacters in helmv3 registryAliases give commit-access users command executionCVE-2024-58376 · Renovate (helmv3 manager, registryAliases handling)Critical
- Citrix NetScaler ADC and Gateway: unauthenticated remote compromise of the applianceCVE-2026-19490 · Citrix NetScaler ADC / GatewayCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.