ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 17 sources: “GitLab CVSS 10.0 Path Traversal CVE-2026-85706 Probed in the Wild One Day After Patch, Added to CISA KEV” — merged summary and timeline →

GitLab security advisory (AV26-917)

highAdvisory exploited in the wildimportance 72CVE-2026-85706
AI summary · glm-5.3-flash

Canada's Cyber Centre warns GitLab versions before 19.1.8, 19.2.6 and 19.3.2 are affected; CISA added CVE-2026-85706 to KEV.

The Canadian Centre for Cyber Security issued advisory AV26-917 on September 11, 2026, warning that GitLab versions prior to 19.1.8, 19.2.6, and 19.3.2 are affected by vulnerabilities. CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on the same date. The Cyber Centre urges users and administrators to review the advisory links and apply GitLab's critical patch release updates.

  • Advisory AV26-917 covers GitLab versions prior to 19.1.8, 19.2.6, and 19.3.2
  • CISA added CVE-2026-85706 to the KEV catalog on September 11, 2026
  • Administrators urged to apply GitLab critical patch release updates

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-85706
Unauthenticated Path Traversal Arbitrary File Read in GitLab CE/EE

CVE-2026-85706 is a path traversal flaw (CWE-35) in GitLab Community Edition and Enterprise Edition in which the repository commits API does not properly confine file paths and does not enforce authentication, allowing an unauthenticated attacker to read arbitrary files from the GitLab server. It is triggered by sending a crafted unauthenticated request to the commits API that supplies traversal sequences moving outside the intended repository path. An attacker gains the ability to read arbitrary files on the host, which can expose configuration files, certificates, and stored credentials or keys; related reporting on the recent GitLab patch wave also notes credential theft and code execution flaws, though this CVE itself is the file-read issue. All self-managed GitLab CE and EE deployments are in scope, and CISA did not publish specific affected version ranges in this data. The flaw was added to CISA's KEV catalog on 2026-09-11 and is being actively probed and exploited in the wild within a day of disclosure, with three public proof-of-concept repositories available; ransomware use is not yet confirmed.

Do: Upgrade GitLab CE/EE to the patched release identified in GitLab's security advisory (no specific fixed version number is provided in this data), prioritizing internet-facing instances in line with CISA BOD 26-04; if patching is not immediately possible, restrict exposure and review access logs for unauthenticated requests to the commits API containing path traversal sequences. Because arbitrary file read can expose server-side secrets, inventory and rotate credentials, tokens, and keys stored on or reachable by affected GitLab hosts.

10.012% KEV PoC ×9
  • GitLab Community Edition
  • GitLab Enterprise Edition
massLikely >1,000,000 aggregate users across hundreds of thousands of self-managed CE/EE deployments, with tens of thousands of instances directly exposed to the…
Full article91 words · extracted from cyber.gc.ca · click to collapse

Serial Number: AV26-917
Date: September 11, 2026

As of September 10, 2026, GitLab is affected by vulnerabilities in the following product:

  • GitLab
    • Prior to 19.1.8
    • Prior to 19.2.6
    • Prior to 19.3.2

On September 11, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917