added to CISA Known Exploited catalog
GitLab had a critical flaw that let unauthenticated users read arbitrary files from the server. The flaw affected self-managed GitLab installations.
- Severity
- CriticalCVSS 3.1 · 10.0 · docs.gitlab.com
- Fix
- Fixed in 19.1.8
- Weakness
- CWE-35
- Affects
- Multiple Vendors+2 more
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Sep 11, 2026
- Federal fix deadline
- Sep 14, 2026
How it works
- An unauthenticated user could reach GitLab's repository commits API.
- Under certain conditions, a request could escape the allowed repository path.
- GitLab could then read arbitrary files from its server because path restrictions and authentication checks failed.
What to do
Check your self-managed GitLab version and compare it with the affected ranges in the GitLab security release. GitLab.com is already patched, and GitLab Dedicated customers do not need to take action.
Upgrade self-managed GitLab CE or EE to 19.1.8, 19.2.6, or 19.3.2, matching your supported release branch.
Technical details
Affected software: Multiple Vendors, GitLab, Community Edition and Enterprise Edition
CVE-2026-85706 is a path traversal issue in the GitLab CE/EE repository commits API. GitLab rated it CVSS 10.0 because an unauthenticated user could read arbitrary server files, with confidentiality and integrity impact.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Open in FIRST.org calculatorReferences
- docs.gitlab.com · patch-release-gitlab-19-3-2-released (patches) patch release notes
- handbook.gitlab.com · releases patch release notes
- docs.gitlab.com · releases patch release notes
- cve.org · CVERecord vdb entry
- nvd.nist.gov · CVE-2026-85706 vdb entry
- about.gitlab.com · faq GitLab Security Releases
- gitlab.com · issues GitLab Security Releases
- about.gitlab.com · gitlab-instance-security-best-practices GitLab Security Releases
- gitlab-com.gitlab.io · explain GitLab Security Releases
- hackerone.com · s3ntago GitLab Security Releases
- hackerone.com · kyyblin GitLab Security Releases
- hackerone.com · joaxcar GitLab Security Releases
- hackerone.com · yvvdwf GitLab Security Releases
- hackerone.com · a_m_a_m GitLab Security Releases
- hackerone.com · nwicks GitLab Security Releases
- hackerone.com · hunter0xp7 GitLab Security Releases
- hackerone.com · xorz GitLab Security Releases
- hackerone.com · theluci GitLab Security Releases
- hackerone.com · 0xoroot GitLab Security Releases
- securityonline.info · gitlab-vulnerabilities-cve-2026-85706-cvss-10 SecurityOnline
- cybersecuritynews.com · gitlab-patches-critical-flaws Cyber Security News
- bleepingcomputer.com · gitlab-urges-users-to-patch-max-severity-path-traversal-flaw BleepingComputer
- thehackernews.com · gitlab-cvss-10-file-read-flaw-draws-in.html TheHackerNews
- cyber.gc.ca · gitlab-security-advisory-av26-917 CCCS Canada
- cisa.gov · known-exploited-vulnerabilities-catalog CCCS Canada
- cert.se · gitlab-rattar-kritiska-sarbarheter.html CERT-SE