GitLab disclosed and patched CVE-2026-85706 on September 10, a maximum-severity (CVSS 10.0) path traversal vulnerability in its repository commits API stemming from improper path confinement and missing authentication enforcement. The flaw allowed an unauthenticated attacker to read arbitrary files, including log files and GitLab-specific configuration files, from any GitLab server that hosted at least one public project, potentially exposing credentials, secrets and other sensitive information. The vulnerability affected GitLab Community Edition and Enterprise Edition versions 18.7 through 19.1.7, 19.2 before 19.2.6, and 19.3 before 19.3.2. GitLab released patched builds 19.1.8, 19.2.6 and 19.3.2. Security firm watchTowr said it observed active probing of internet-exposed GitLab servers for the flaw beginning at 06:00 UTC on September 11, one day after disclosure. The Cybersecurity and Infrastructure Security Agency added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11, setting a September 14 remediation deadline for Federal Civilian Executive Branch agencies. Because GitLab is widely used to host private source code and CI/CD credentials for both public and enterprise repositories, unpatched self-hosted instances remain at risk of credential theft and further compromise until upgraded.
Global Cybersecurity and Data 13 Sept 2026
GitLab Patches Maximum-Severity Flaw After Active Exploitation Attempts Begin
GitLab patched CVE-2026-85706, a maximum-severity (CVSS 10.0) path traversal flaw in its repository commits API that let unauthenticated attackers read arbitrary files from GitLab servers, after CISA added it to its Known Exploited Vulnerabilities catalog on September 11 following reports of active internet-wide probing.
Source: The Hacker News, September 11, 2026
Comments
0 commentsNo comments yet — be the first.