Zero Day Room
Live
Vulnerabilities

GitLab Patches Critical CVSS 10 File-Read Vulnerability

GitLab has patched a maximum-severity path traversal flaw, CVE-2026-85706, which allows unauthenticated file reads.

GitLab has patched a maximum-severity path traversal flaw, CVE-2026-85706, which allows unauthenticated file reads

GitLab has released security patches for a critical vulnerability that allows unauthenticated attackers to read arbitrary files from servers. The flaw, tracked as CVE-2026-85706 and rated with the maximum CVSS score of 10.0, is already being probed in the wild.

According to GitLab, the issue is a path traversal bug in the repository commits API. It results from improper path confinement and missing authentication enforcement. An attacker could exploit this to read sensitive files from the GitLab server under specific conditions.

Affected Versions and Patches

The vulnerability impacts multiple versions of GitLab Community Edition (CE) and Enterprise Edition (EE). Patches are available in the latest releases.

Product EditionAffected Version RangesPatched In Version
GitLab CE & EEAll versions from 18.7 before 19.1.819.1.8
GitLab CE & EEAll versions from 19.2 before 19.2.619.2.6
GitLab CE & EEAll versions from 19.3 before 19.3.219.3.2

Organizations running self-managed instances exposed to the internet must apply these updates immediately. If public access is not required, limiting it is also advised.

Active Exploitation and Attacker Appeal

Threat intelligence firm watchTowr reported active in-the-wild probes for the vulnerability starting at 06:00 UTC on September 11, 2026. The firm's head of threat intelligence, Jake Knott, stated that exploitation requires at least one public project to exist on the target instance.

Knott explained the clear appeal of GitLab to attackers. Unauthorized access can provide source code, CI/CD secrets, and credentials. It also offers the ability to inject code into build pipelines, poisoning anything downstream. This method has been a favorite of attackers throughout the year, he noted.

This is the second critical GitLab vulnerability in recent weeks. It follows CVE-2026-19478, a GraphQL code injection flaw that was almost immediately exploited. Knott warned defenders have limited time. "Based on the history, the transition of this vulnerability to indiscriminate mass exploitation is likely not far away," he said.

Additional Critical Patch and Detection

GitLab's same batch of updates also fixes another critical flaw in the Enterprise Edition. Tracked as CVE-2026-87719 with a CVSS score of 9.9, it is an insecure deserialization bug. GitLab states it could allow an authenticated user with Duo Chat access to obtain Advanced Search configurations and sensitive credentials by using a specially crafted GraphQL subscription argument.

For the primary file-read vulnerability, watchTowr recommends reviewing log files for signs of attempted exploitation. Organizations should look for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs that contain 'file.Path' parameters. Identifying these requests can help detect probing or attack attempts before full compromise occurs.

Related coverage

More from Vulnerabilities