CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

GitLab urges users to patch max severity path traversal flaw

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7063

As cited

Copy frozen at (site build).

vulnerabilities

GitLab urges users to patch max severity path traversal flaw

GitLab disclosed a maximum-severity path traversal vulnerability tracked as CVE-2026-85706 and advised users to apply patches immediately. The flaw allows attackers to traverse the file system and access sensitive data or execute code on affected instances.

Why it matters: GitLab administrators managing self-hosted or cloud instances must patch immediately to prevent unauthorized file access and potential remote code execution on their systems.

VendorsGitLab
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

GitLab urges users to patch max severity path traversal flaw

GitLab disclosed a maximum-severity path traversal vulnerability tracked as CVE-2026-85706 with a CVSS score of 10.0 and urged users to patch immediately. The flaw is under active exploitation and has been added to vulnerability tracking lists despite not yet appearing on official CISA catalogs.

Why it matters: GitLab administrators must apply patches urgently to prevent attackers from exploiting this critical path traversal flaw that is actively being weaponized in the wild.

VendorsGitLab
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

GitLab urges users to patch max severity path traversal flaw

GitLab has urged users to patch CVE-2026-85706, a maximum-severity path traversal vulnerability affecting its servers. The flaw carries a CVSS score of 10.0 and is currently under active exploitation.

Why it matters: GitLab administrators must patch immediately: this vulnerability is on the Known Exploited Vulnerabilities (KEV) catalog and exploitation is already underway in the wild.

VendorsGitLab
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary