← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 14, 2026 · 10:02via Rapid7 Blog

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Brief

Overview

On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3. 1 score of 10. 0 .

According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.

On September 11, 2026, CVE-2026-85706 was added to the U. S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Read more on Rapid7 Blog→