Unauthenticated GraphQL mutation exploit attempt against GitLab CVE-2026-19478
This rule detects potentially malicious, unauthenticated GraphQL mutation requests targeting common data modification operations ('delete', 'destroy', 'remove', 'update'). By checking for missing Authorization and Session tokens during frequent mutation attempts, it identifies potential exploitation attempts or unauthorized data manipulation attempts against an exposed GraphQL endpoint.
Microsoft Sentinel (KQL)

