started · updated
GitLab vulnerability exploited shortly after disclosure
A critical path traversal vulnerability in GitLab, tracked as CVE-2026-85706, is being actively exploited in the wild. The flaw, which carries a maximum CVSS score of 10/10, allows unauthenticated users to read arbitrary files from a GitLab server using a single HTTP POST request to the commits API.
Security firm WatchTowr reported observing exploitation attempts within hours of the vulnerability's public disclosure. The flaw affects various Community Edition (CE) and Enterprise Edition (EE) versions, specifically those from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. While GitLab.com has been patched, approximately 20,000 self-managed instances globally remain at risk.
The Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog, mandating that agencies remediate the issue by September 14. Successful exploitation could grant attackers access to sensitive source code, CI/CD secrets, and credentials, potentially allowing them to poison downstream build pipelines.