GitLab CVSS 10.0 Path Traversal CVE-2026-85706 Probed in the Wild One Day After Patch, Added to CISA KEV
GitLab's September 10, 2026 patches for CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal enabling arbitrary file reads via a single HTTP request, drew WatchTowr-observed internet-wide probing within one day and a CISA KEV listing with a September 14…
On September 10, 2026, GitLab released versions 19.1.8, 19.2.6, and 19.3.2 for CE/EE, fixing CVE-2026-85706, a maximum-severity (CVSS 3.1 10.0) unauthenticated path traversal in the repository commits API caused by improper path confinement and missing authentication enforcement. A single crafted HTTP POST to /api/v4/projects/{id}/repository/commits/ containing a file.path parameter lets an unauthenticated attacker read arbitrary files with no account or user interaction; The Hacker News notes exploitation requires at least one public project to exist on the instance, and the flaw was reported via GitLab's HackerOne bug bounty and credited to researcher s3ntago. Readable files can include credentials, tokens, SSH keys, database and deploy credentials, CI/CD variables, configuration files, and cloud secrets useful for reconnaissance and follow-on intrusions; GBHackers reports no ransomware use has been confirmed. Sources disagree on the CWE classification: GBHackers cites CWE-35, while Rapid7 cites CWE-22. Affected versions are 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 (CISA frames the ranges as 18.7-19.1.7, 19.2-19.2.5, and 19.3-19.3.1). GitLab.com and Dedicated offerings were already fixed or unaffected, so self-managed operators must upgrade immediately. The same release fixes 17 other vulnerabilities, including CVE-2026-87719 (CVSS 9.9), an insecure deserialization flaw in GitLab EE's GraphQL subscription serializer that lets authenticated Duo Chat users access Advanced Search configurations and sensitive credentials via crafted GraphQL subscription arguments, plus six high-severity bugs covering RCE, CI/CD variable access, XSS, and denial of service. The Hacker News notes CVE-2026-85706 follows the recently exploited GitLab GraphQL code injection bug CVE-2026-19478. WatchTowr detected the first in-the-wild probes starting 06:00 UTC on September 11, 2026 - one day after disclosure - describing internet-wide probing that, per The Register, continued against internet-facing self-hosted instances over the weekend, and warning that mass exploitation is likely based on past GitLab flaws. CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11, 2026, citing active exploitation, with a federal remediation deadline of September 14, 2026 under Binding Operational Directive 26-04, which also requires forensic triage; Infosecurity Magazine alone reports a September 15 deadline. CyberScoop, in earlier…
- CVE-2026-85706 is a CVSS 3.1 10.0 unauthenticated path traversal in GitLab CE/EE's repository commits API (improper path confinement plus missing authentication enforcement) allowing arbitrary file reads via a single crafted HTTP POST to…
- Affected versions: 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 (CISA: 18.7-19.1.7, 19.2-19.2.5, 19.3-19.3.1); fixes shipped September 10, 2026 in 19.1.8, 19.2.6, and 19.3.2, credited to researcher s3ntago via HackerOne.
- WatchTowr observed the first in-the-wild probes starting 06:00 UTC on September 11, 2026 - one day after the patch - with internet-wide probing of self-hosted instances continuing over the weekend; mass exploitation is considered likely…
- CISA added CVE-2026-85706 to its KEV catalog on September 11, 2026 citing active exploitation, with a federal remediation deadline of September 14, 2026 under BOD 26-04 (which also requires forensic triage); Infosecurity Magazine alone…
- Exploitation requires at least one public project on the instance (The Hacker News); GitLab.com and Dedicated offerings were already fixed or unaffected, so self-managed operators must upgrade immediately.
- Arbitrary file reads can expose credentials, tokens, SSH keys, database and deploy credentials, CI/CD variables, configuration files, and cloud secrets enabling follow-on intrusions; GBHackers reports no ransomware use has been confirmed.
- The same release fixes 17 other vulnerabilities, including CVE-2026-87719 (CVSS 9.9), an insecure deserialization flaw in GitLab EE's GraphQL subscription serializer letting authenticated Duo Chat users access Advanced Search…
- Sources disagree on the CWE classification: GBHackers cites CWE-35, while Rapid7 cites CWE-22.
Coverage timelineoldest first · each row is one article
- · 4d agoGitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution
Cyber Security News· 72
GitLab patched a CVSS 10.0 path traversal (CVE-2026-85706) plus deserialization and buffer-overflow flaws, urging self-managed users to update immediately.
- · 4d agoGitLab urges users to patch max severity path traversal flaw
BleepingComputer· 65
GitLab urges self-managed users to immediately patch a maximum-severity path traversal flaw (CVE-2023-2825) enabling unauthenticated arbitrary file reads.
- · 4d agoCISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories· 72
CISA added CVE-2026-85706, an actively exploited GitLab path traversal flaw, to its KEV Catalog, requiring federal agencies to prioritize patching.
- · 4d agoGitLab Vulnerability Exploited One Day After Disclosure
SecurityWeek· 85
WatchTowr observed in-the-wild exploitation of critical GitLab path traversal CVE-2026-85706 one day after disclosure, letting unauthenticated attackers read arbitrary files.
- · 4d agoGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
The Hacker News· 80
GitLab patched CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal enabling arbitrary file reads, already probed in the wild.
- · 4d agoGitLab’s critical flaw is already drawing internet-wide probes
CyberScoop· 78
GitLab patches two critical flaws (CVE-2026-85706 CVSS 10.0, CVE-2026-87719) as WatchTowr observes internet-wide probing of the unauthenticated file-read bug.
- · 4d agoCVE-2026-85706 | GitLab CE/EE Repository Commits API Path Traversal Vulnerability
Horizon3.ai· 75
GitLab patches CVSS 10.0 path traversal CVE-2026-85706 letting unauthenticated attackers read arbitrary files on self-managed CE/EE servers.
- · 4d agoGitLab security advisory (AV26-917)
Canadian Centre for Cyber Security· 72
Canada's Cyber Centre warns GitLab versions before 19.1.8, 19.2.6 and 19.3.2 are affected; CISA added CVE-2026-85706 to KEV.
- · 3d agoCISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
Cyber Security News· 88
CISA added actively exploited GitLab path traversal flaw CVE-2026-85706 (CVSS 10.0) to its KEV catalog, setting a September 14 federal patch deadline.
- · 3d agoCISA Warns of Critical GitLab Vulnerability Exploited in Attacks
GBHackers· 80
CISA added actively exploited GitLab path traversal flaw CVE-2026-85706 to its KEV catalog, warning unauthenticated attackers can read arbitrary files including secrets.
- · 2d agoGitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Security Affairs· 90
GitLab path traversal CVE-2026-85706 (CVSS 10.0) was actively probed and exploited within 24 hours of disclosure and added to CISA's KEV catalog.
- · 1d agoCISA: Hackers now exploit max severity GitLab flaw in attacks
BleepingComputer· 30
CISA added max-severity GitLab CVE-2026-85706 to its exploited-flaws catalog after watchTowr observed probing of unpatched servers.
- · 1d agoHackers Exploit Maximum Severity Flaw in GitLab
Infosecurity Magazine· 82
CISA added GitLab path traversal CVE-2026-85706 to KEV after in-the-wild probes; unauthenticated attackers can read arbitrary files.
- · 1d agoCVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
Rapid7 Blog· 88
CVE-2026-85706, a CVSS 10.0 unauthenticated path traversal in GitLab CE/EE, is actively exploited and was added to CISA's KEV catalog.
- · 1d agoPerfect-10 GitLab bug under attack days after patch lands
The Register · Security· 90
CISA confirms active exploitation of CVSS 10.0 GitLab path traversal flaw CVE-2026-85706 days after patches shipped, enabling unauthenticated arbitrary file reads.
- · 1d agoMaximum Severity GitLab Flaw Puts Supply Chains at Risk
Dark Reading· 60
GitLab CVE-2026-85706 is a maximum-severity CVSS 10.0 path traversal flaw affecting Community and Enterprise Editions, risking supply chain compromise.
- · 20h agoA maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
CSO Online· 88
GitLab patched maximum-severity CVE-2026-85706, an unauthenticated path traversal enabling arbitrary file reads; CISA added it to KEV amid observed in-the-wild probes.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-2825 | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups. NVD description · AI analysis pending | 7.5 | 72% |
| — | ||
| CVE-2026-19478 | Unauthenticated GraphQL Code Injection in GitLab CE/EE Enables Data Tampering GitLab has patched a critical (CVSS 9.1) code injection flaw (CWE-94) in how GitLab Community Edition (CE) and Enterprise Edition (EE) process GraphQL directives. Under certain conditions, an unauthenticated remote attacker can abuse a GraphQL directive to modify or delete public projects and user data on affected instances, requiring no privileges or user interaction; the impact is to integrity and availability, not confidentiality. Affected versions span all GitLab CE/EE releases from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4, which covers self-managed installations as well as the same codebase that powers the GitLab.com SaaS. News reports indicate the flaw came under active exploitation within days of disclosure, and EPSS assigns a 5.8% probability of exploitation within 30 days (93rd percentile). It is not yet listed in CISA's KEV catalog and no public proof-of-concept is known, but defenders should treat it as an actively exploited, unauthenticated, high-impact issue. Do: Upgrade all GitLab CE/EE instances to 18.11.11, 19.0.8, 19.1.6, or 19.2.4 (or later) immediately, prioritizing internet-facing instances given confirmed active exploitation. Until patched, restrict unauthenticated access to the GraphQL API endpoint at the network or WAF layer. Review instance audit logs and public projects for signs of unauthorized modifications or deletions of projects and user data. | 9.1 | 6% |
| massmillions of users (GitLab.com SaaS runs the same code) plus tens of thousands of internet-exposed self-managed CE/EE instances | ||
| CVE-2026-85706 | Unauthenticated Path Traversal Arbitrary File Read in GitLab CE/EE CVE-2026-85706 is a path traversal flaw (CWE-35) in GitLab Community Edition and Enterprise Edition in which the repository commits API does not properly confine file paths and does not enforce authentication, allowing an unauthenticated attacker to read arbitrary files from the GitLab server. It is triggered by sending a crafted unauthenticated request to the commits API that supplies traversal sequences moving outside the intended repository path. An attacker gains the ability to read arbitrary files on the host, which can expose configuration files, certificates, and stored credentials or keys; related reporting on the recent GitLab patch wave also notes credential theft and code execution flaws, though this CVE itself is the file-read issue. All self-managed GitLab CE and EE deployments are in scope, and CISA did not publish specific affected version ranges in this data. The flaw was added to CISA's KEV catalog on 2026-09-11 and is being actively probed and exploited in the wild within a day of disclosure, with three public proof-of-concept repositories available; ransomware use is not yet confirmed. Do: Upgrade GitLab CE/EE to the patched release identified in GitLab's security advisory (no specific fixed version number is provided in this data), prioritizing internet-facing instances in line with CISA BOD 26-04; if patching is not immediately possible, restrict exposure and review access logs for unauthenticated requests to the commits API containing path traversal sequences. Because arbitrary file read can expose server-side secrets, inventory and rotate credentials, tokens, and keys stored on or reachable by affected GitLab hosts. | 10.0 | 12% | KEV PoC ×9 |
| massLikely >1,000,000 aggregate users across hundreds of thousands of self-managed CE/EE deployments, with tens of thousands of instances directly exposed to the… | |
| CVE-2026-87719 | Authenticated GraphQL Subscription Flaw Leaks Search Credentials in GitLab EE GitLab EE contains a critical (CVSS 9.9) deserialization flaw (CWE-502) in which an authenticated user with Duo Chat access can pass a specially crafted GraphQL subscription argument that bypasses serialization and performs a server object lookup. Via this bypass, the attacker can obtain Advanced Search instance configurations and the sensitive credentials they contain. Because the attack requires only a low-privileged account with Duo Chat access over the network, with no user interaction, any EE deployment where Duo Chat is enabled is potentially exposed, including both self-managed instances and GitLab.com. Affected versions are EE 18.3 and later before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. No public proof-of-concept or CISA KEV listing exists for this CVE as of now, though related GitLab flaws disclosed in the same cycle are reportedly drawing internet-wide probing. Do: Upgrade GitLab EE to 19.3.2, 19.2.6, or 19.1.8 depending on the version track in use. Until patched, restrict Duo Chat access to trusted users or disable it where feasible, and audit logs for unusual GraphQL subscription activity by authenticated Duo Chat users. After upgrading, rotate Advanced Search (Elasticsearch/OpenSearch) credentials and review search cluster configurations for signs of access. | 9.9 | — |
| largelikely hundreds of thousands of paid-tier (Duo-enabled) users across GitLab.com and self-managed EE instances |