GitLab disclosed and patched CVE-2026-85706 on September 10, a maximum-severity (CVSS 10.0) path traversal vulnerability in its repository commits API stemming from improper path confinement and missing authentication enforcement. The flaw allowed an unauthenticated attacker to read arbitrary files, including log files and GitLab-specific configuration files, from any GitLab server that hosted at least one public project, potentially exposing credentials, secrets and other sensitive information. The vulnerability affected GitLab Community Edition and Enterprise Edition versions 18.7 through 19.1.7, 19.2 before 19.2.6, and 19.3 before 19.3.2. GitLab released patched builds 19.1.8, 19.2.6 and 19.3.2. Security firm watchTowr said it observed active probing of internet-exposed GitLab servers for the flaw beginning at 06:00 UTC on September 11, one day after disclosure. The Cybersecurity and Infrastructure Security Agency added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11, setting a September 14 remediation deadline for Federal Civilian Executive Branch agencies. Because GitLab is widely used to host private source code and CI/CD credentials for both public and enterprise repositories, unpatched self-hosted instances remain at risk of credential theft and further compromise until upgraded.