2026-09-09 · Application security
GitLab GraphQL unauthenticated access: what scanners miss in your API
CVE-2026-19478 is a CVSS 9.4 GraphQL authorization flaw, not RCE. Why unauthenticated writes on public objects still slip past scanners, and what to test on your own schema.