As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions
GitLab patched a path traversal vulnerability in its Community and Enterprise Editions affecting the repository commits application programming interface (API). Unauthenticated attackers can read arbitrary files due to improper path confinement and missing authentication controls. The Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-85706 has a CVSS score of 10.0, appears in CISA's Known Exploited Vulnerabilities catalog, and public exploit code is available.
Why it matters: Administrators of internet-accessible, self-hosted GitLab instances must immediately patch to versions 19.1.8, 19.2.6, 19.3.2 or later to prevent unauthenticated file disclosure and credential theft.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions
GitLab patched a path traversal vulnerability in its Community and Enterprise Editions that allows unauthenticated users to read arbitrary files through the repository commits application programming interface (API). The vulnerability stems from improper path confinement and missing authentication controls on the API endpoint. The flaw is tracked as CVE-2026-85706 with a CVSS score of 10.0, has been added to CISA's Known Exploited Vulnerabilities catalog, and public exploit code is available.
Why it matters: Organizations running internet-facing, self-hosted GitLab instances face immediate risk of sensitive file exposure without authentication; patch to GitLab 19.1.8, 19.2.6, 19.3.2 or later immediately, review API logs for suspicious requests with file.path parameters, and rotate any exposed credentials.
- Source published
- First seen by Cybersecurity Tracker