chiprook
← Security
SecurityOctober 2, 2026, 05:00

CVE-2026-85706: unauthenticated file read in GitLab exploited

GitLab patched CVE-2026-85706, an unauthenticated path traversal in the repository commits API that allows file reads, including gitlab.yml with credentials and keys. Fixes shipped on 10 September 2026 in 19.3.2, 19.2.6 and 19.1.8, and CISA lists the flaw as exploited.

CVE-2026-85706: unauthenticated file read in GitLab exploited
#GitLab#CISA#ZoomEye
Read next
Security

Sizing Self-Managed GitLab Exposure After CVE-2026-85706

Security

F5 BIG-IP APM CVE-2026-94127: unauthenticated RCE that hardening won't stop

Security

CVE-2026-7273 in Zyxel GS1900 switches allows unauthenticated OS command execution

Security

Metabase CVE-2026-72898: unauthenticated SQL injection exposes the data warehouse