GITHUB-ACTIONS · SEPTEMBER 2026 · CONFIRMED

GitLab Commits API Vulnerability CVE-2026-85706: What You Need to Know

Severity
HIGH
Affected component
gitlab (github-actions)
Patched version
19.1.8 || 19.2.6 || 19.3.2 || nieuwer
CVE-2026-85706

GitLab has patched a critical vulnerability in the commits API that allowed unauthenticated users to read arbitrary files. Users of affected versions should upgrade immediately.

What happened

GitLab has patched a critical vulnerability, tracked as CVE-2026-85706, in the commits API of both Community and Enterprise Editions. This vulnerability allowed unauthenticated users to perform path traversal, enabling them to read arbitrary files on the system. CISA has confirmed that this vulnerability is being exploited in the wild, with public exploit code available. Users of affected versions should upgrade immediately and review their API logs for suspicious activity.

The vulnerability was first flagged on September 12, 2026, and confirmed on September 14, 2026. Affected versions include those below 19.1.8, 19.2.6, and 19.3.2. The patched versions are 19.1.8, 19.2.6, and 19.3.2 or newer. It is recommended to upgrade to one of these versions and to rotate any credentials that may have been exposed.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If gitlab is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using GitLab versions below 19.1.8, 19.2.6, or 19.3.2.

What should I do right now?

Upgrade to GitLab 19.1.8, 19.2.6, 19.3.2 or newer and review your API logs for suspicious activity.

Has this been exploited in the wild?

Yes, this vulnerability is being actively exploited.

Sources

Join the 0Day waitlist →

← Back to all threats