As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
GitLab released an emergency patch on September 10, 2026, for CVE-2026-85706, a critical path traversal vulnerability in the repository commits application programming interface (API) (CVSS 10.0) that permits unauthenticated users to read arbitrary files. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on September 11, 2026, with evidence of active exploitation in the wild. Self-managed GitLab Community Edition and Enterprise Edition instances require immediate upgrade to fixed versions 19.1.8, 19.2.6, or 19.3.2 depending on current deployment version.
Why it matters: Organizations running self-managed GitLab instances face immediate risk from unauthenticated file disclosure; CISA mandated Federal Civilian Executive Branch agencies remediate by September 14, 2026, and all affected deployments should patch outside normal cycles to prevent data exfiltration.
- Source published
- First seen by Cybersecurity Tracker