Jake KnottwatchTowrGitLab Inc.

GitLab patches critical path traversal flaw (CVE-2026-85706) with CVSS 10.0; in-the-wild probes emerge after disclosure, urging immediate patching

GitLab has patched a critical path traversal vulnerability (CVE-2026-85706) with a CVSS score of 10.0, allowing unauthenticated users to access sensitive files. In-the-wild probes have been detected, prompting urgent action for organizations to apply the patch or restrict public access to their GitLab instances.

The Hacker News The Hacker News+1 source12 September 2026 · 02:07 UTC
CuriousCats Full Story

GitLab has addressed a critical path traversal vulnerability (CVE-2026-85706) with a CVSS score of 10.0, affecting its repository commits API. This flaw allows unauthenticated users to read arbitrary files from the server, posing significant risks to sensitive data.1236

The vulnerability stems from improper path confinement and missing authentication enforcement, impacting all versions of GitLab Community Edition (CE) and Enterprise Edition (EE) from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. WatchTowr reported that probes for this vulnerability began on September 11, 2026, indicating active exploitation attempts.4579

According to Jake Knott, head of threat intelligence at WatchTowr, “This is the second instance of a critical severity GitLab vulnerability in recent weeks.” He emphasized that exploitation requires at least one public project to exist, making many organizations vulnerable.8

GitLab released patches on September 10, 2026, in versions 19.3.2, 19.2.6, and 19.1.8. Organizations are urged to apply these patches immediately or restrict public access to their self-hosted instances. Additionally, they should monitor log files for suspicious HTTP POST requests to identify potential exploitation attempts.

The urgency of this situation is underscored by the fact that WatchTowr has already observed behavioral probes against their global honeypot network, indicating that attackers are actively seeking to exploit this vulnerability.

Key Insight
“watchTowr observed active probes starting 06:00 UTC on September 11, 2026, and warns that mass exploitation is likely imminent. The flaw allows unauthenticated file reads, exposing credentials and CI/CD secrets, and also patches a critical deserialization bug (CVE-2026-87719) in GitLab EE.”
CuriousCats studied:
1
The Hacker NewsThe Hacker News
“The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under certain conditions.”
The Hacker News →
2
watchTowr
“On September 10, 2026, GitLab released versions 19.3.2, 19.2.6, and 19.1.8 for GitLab Community Edition and Enterprise Edition.”
watchTowr →
Ask CuriousCats
What is the CVE-2026-85706 flaw?
Who reported the active probes on GitLab?
Why is immediate patching necessary?
Are there similar vulnerabilities in other platforms?
How do GitLab's patches compare with previous updates?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats