Search
Find merged stories by title or summary.
A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single HTTP request. The path traversal flaw results from improper confinement and lack of authentication enforcement in GitLab’s repository commits API, the company reported. Threat actors could exploit it “under certain conditions” and read arbitrary files (credentials, secrets, and other sensitive data) on vulnerable GitLab servers. The company has fixed the vulnerability, which impacts GitLab Community Edition (CE) and Enterprise Edition (EE), and has advised customers with public-facing self-hosted GitLab instances to patch their servers immediately, or remove public access.
Maximum Severity GitLab Flaw Puts Supply Chains at Risk
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3. 1 score of 10. 0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U. S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request may expose SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data. By September 11, active probing and exploitation attempts were already underway. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog. watchTowr researchers are already seeing in-the-wild probes targeting CVE-2026-85706.
NVD-CVE-2026-85706 - nvd.nist.gov
NVD-CVE-2026-85706 nvd. nist. gov
CISA Warns of Critical GitLab Path Traversal Flaw Exploited to Read Arbitrary Server Files
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab path traversa l vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after evidence that the flaw is being actively exploited. The vulnerability affects both GitLab Community Edition (CE) and Enterprise Edition (EE). CVE-2026-85706 allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server. The issue stems from improper path confinement and missing authentication enforcement in the repository commits API, allowing attacker-controlled path values to escape the intended repository directory. CISA Warns of Critical GitLab Path Traversal Flaw The flaw is categorized as CWE-35, a path traversal weakness that occurs when an application fails to properly restrict file-path operations to an expected directory.
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706 , to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw. The issue affects GitLab Community Edition and Enterprise Edition deployments and carries a maximum CVSS severity score of 10.0. CVE-2026-85706 is a path traversal vulnerability in GitLab’s repository commits API. GitLab said that, under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication enforcement to read arbitrary files from an affected GitLab server. Path traversal flaws occur when an application fails to properly restrict file paths supplied through requests.
GitLab security advisory (AV26-917)
Serial Number: AV26-917 Date: September 11, 2026 As of September 10, 2026, GitLab is affected by vulnerabilities in the following product: • GitLab • Prior to 19.1.8 • Prior to 19.2.6 • Prior to 19.3.2 On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8 • GitLab Docs • GitLab release notes • GitLab Docs • CISA KEV: CVE-2026-85706 GitLab security advisory (AV26-917) - Canadian Centre for Cyber Security
GitLab’s critical flaw is already drawing internet-wide probes
GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws. The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. GitLab said its own hosted service already runs the fixed code, and that customers of its single-tenant Dedicated offering are not impacted. The more serious of the two flaws, tracked as CVE-2026-85706 , sits in the interface that handles repository commits. GitLab said that under certain conditions an attacker could read any file on the server, because the code failed to confine file paths properly and did not enforce authentication.
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [... ]
[CISA] CVE-2026-85706 - Confirmed Exploitation
CVE-2026-85706 Catalog: CISA Status: Confirmed Exploited: Yes Status Updated: 2026-09-11 00:00 UTC Evidence Sources: 1 First Seen: 2026-09-11 Asserted: 2026-09-11
You've reached the end of current stories for this search.
