CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7154

As cited

Copy frozen at (site build).

vulnerabilities

NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions

GitLab patched a path traversal vulnerability in its Community and Enterprise Editions affecting the repository commits application programming interface (API). Unauthenticated attackers can read arbitrary files due to improper path confinement and missing authentication controls. The Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-85706 has a CVSS score of 10.0, appears in CISA's Known Exploited Vulnerabilities catalog, and public exploit code is available.

Why it matters: Administrators of internet-accessible, self-hosted GitLab instances must immediately patch to versions 19.1.8, 19.2.6, 19.3.2 or later to prevent unauthenticated file disclosure and credential theft.

VendorsGitLab
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions

GitLab patched a path traversal vulnerability in its Community and Enterprise Editions that allows unauthenticated users to read arbitrary files through the repository commits application programming interface (API). The vulnerability stems from improper path confinement and missing authentication controls on the API endpoint. The flaw is tracked as CVE-2026-85706 with a CVSS score of 10.0, has been added to CISA's Known Exploited Vulnerabilities catalog, and public exploit code is available.

Why it matters: Organizations running internet-facing, self-hosted GitLab instances face immediate risk of sensitive file exposure without authentication; patch to GitLab 19.1.8, 19.2.6, 19.3.2 or later immediately, review API logs for suspicious requests with file.path parameters, and rotate any exposed credentials.

VendorsGitLab
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary