CVE-2026-85706: unauthenticated file read in GitLab exploited
GitLab patched CVE-2026-85706, an unauthenticated path traversal in the repository commits API that allows file reads, including gitlab.yml with credentials and keys. Fixes shipped on 10 September 2026 in 19.3.2, 19.2.6 and 19.1.8, and CISA lists the flaw as exploited.
- Flaw allows unauthenticated file read via path traversal in commits API
- Fixed on 10 September 2026 in GitLab 19.3.2, 19.2.6 and 19.1.8
- CISA rates the case as exploited and automatable
- ZoomEye counted 1,317,044 GitLab assets on 25 September 2026
Read next
Security