CYBERSECURITYTRACKER
TRACKING7,283 stories in this site build1,521 vulnerability news stories in this site build
Permanent story citation

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7208

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

GitLab released an emergency patch on September 10, 2026, for CVE-2026-85706, a critical path traversal vulnerability in the repository commits application programming interface (API) (CVSS 10.0) that permits unauthenticated users to read arbitrary files. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on September 11, 2026, with evidence of active exploitation in the wild. Self-managed GitLab Community Edition and Enterprise Edition instances require immediate upgrade to fixed versions 19.1.8, 19.2.6, or 19.3.2 depending on current deployment version.

Why it matters: Organizations running self-managed GitLab instances face immediate risk from unauthenticated file disclosure; CISA mandated Federal Civilian Executive Branch agencies remediate by September 14, 2026, and all affected deployments should patch outside normal cycles to prevent data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary