Critical GitLab Flaw (CVE-2026-19478) Lets Unauthenticated Attackers Rewrite Public Projects
A critical code-injection vulnerability in GitLab, tracked as CVE-2026-19478 (CVSS 9.4), allows unauthenticated attackers to modify or delete publicly accessible projects and rewrite their data — with no credentials required.…