GitLab CVE-2026-85706 Added to CISA KEV
CISA added CVE-2026-85706 to KEV: a path traversal in GitLab CE/EE letting unauthenticated attackers read arbitrary files.
CVE-2026-85706 is a severe path traversal flaw in GitLab CE and EE that permits unauthenticated remote actors to retrieve arbitrary files from affected self-managed deployments. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating exploitation has been observed. Organizations running self-managed GitLab instances should prioritize patching.