Maximum-Severity GitLab Path Traversal CVE-2026-85706 Under Active Exploitation; CISA Adds Flaw to KEV Catalog
CVE-2026-85706, a CVSSv3.1 10.0 unauthenticated path traversal in GitLab CE/EE's repository commits API enabling arbitrary file reads from self-managed servers, was patched September 10 in versions 19.1.8, 19.2.6, and 19.3.2; watchTowr detected in-the-wild…
CVE-2026-85706 is a maximum-severity path traversal flaw (CWE-22, CVSSv3.1 10.0) in GitLab Community Edition and Enterprise Edition's repository commits API. Caused by improper path confinement and missing authentication enforcement, it lets an unauthenticated attacker read arbitrary files — including configuration data and credentials — from affected self-managed servers via a single HTTP POST request with a crafted file.path parameter. The bug was reported through GitLab's HackerOne bug bounty and affects versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2; fixes shipped September 10 in 19.1.8, 19.2.6, and 19.3.2. CISA added the CVE to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed. Sources disagree on the federal deadline: Rapid7 reports the KEV addition occurred September 11, 2026 with a September 14 remediation deadline and BOD 26-04 forensic triage requirements, while Infosecurity Magazine cites a September 15 federal patch deadline. watchTowr (spelled 'Watchtower' in one report) detected in-the-wild probes for the bug on September 11, targeting internet-facing self-hosted instances, and warns widespread exploitation is likely to follow quickly. Defenders are urged to patch immediately, hunt logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.path parameters, and rotate any potentially exposed secrets. The same September 10 release also fixes 17 other vulnerabilities, including CVE-2026-87719, a CVSS 9.9 insecure deserialization flaw in GitLab EE. Dark Reading notes the flaw could enable repository tampering with software supply chain risk, though that report does not mention active exploitation. GitLab is used by roughly 50% of the Fortune 100 and has over 50 million registered users.
- CVE-2026-85706 is a maximum-severity (CVSSv3.1 10.0) path traversal (CWE-22) in GitLab CE/EE's repository commits API, caused by improper path confinement and missing authentication enforcement
- Unauthenticated attackers can read arbitrary files, including configuration data and credentials, from self-managed GitLab servers via a single HTTP POST request
- Affected versions: GitLab CE/EE 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
- Fixes shipped September 10, 2026 in GitLab versions 19.1.8, 19.2.6, and 19.3.2
- CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog citing active exploitation; Rapid7 dates the addition to September 11, 2026
- Sources disagree on the federal deadline: September 14 remediation deadline with BOD 26-04 forensic triage requirements (Rapid7) versus September 15 federal patch deadline (Infosecurity Magazine)
- watchTowr detected in-the-wild probes for the bug on September 11, targeting internet-facing self-hosted instances, and warns widespread exploitation is likely to follow quickly
- Detection guidance: hunt for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.path parameters; rotate any potentially exposed secrets after patching
Coverage timelineoldest first · each row is one article
- · 12d agoHackers Exploit Maximum Severity Flaw in GitLab
Infosecurity Magazine· 82
CISA added GitLab path traversal CVE-2026-85706 to KEV after in-the-wild probes; unauthenticated attackers can read arbitrary files.
- · 12d agoCVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
Rapid7 Blog· 88
CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal in GitLab CE/EE, is actively exploited and was added to CISA's KEV catalog.
Vulnerabilities in this storyAll →
- CVE-2026-8570610.091%Unauthenticated Path Traversal Arbitrary File Read in GitLab CE/EEpublished · GitLab Community Edition KEV PoC ×11