CISA_KEV · SEPTEMBER 2026 · CONFIRMED

GitLab File-Read Flaw CVE-2026-85706: Critical Threat Alert

Severity
HIGH
Affected component
gitlab (other)
Patched version
Not yet available
CVE-2026-85706

GitLab Community Edition and Enterprise Edition have a critical path traversal vulnerability that allows unauthenticated users to read arbitrary files. This is due to improper path confinement and missing authentication enforcement in the repository commits API.

What happened

The vulnerability, tracked as CVE-2026-85706, was first flagged on September 11, 2026, and confirmed on the same day. It has been exploited in the wild, as reported by multiple independent sources including CISA and The Hacker News. The flaw allows attackers to read sensitive files on the server, potentially leading to data breaches and further exploitation.

The vulnerability affects GitLab Community Edition and Enterprise Edition, but no authoritative version range has been published yet. Users are advised to upgrade to the latest version of GitLab to mitigate this risk.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If gitlab is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using GitLab Community Edition or Enterprise Edition, you may be affected. No specific version range has been published yet, so it is recommended to upgrade to the latest version as a precaution.

What should I do right now?

Upgrade to the latest version of GitLab Community Edition and Enterprise Edition. Monitor official security advisories for updates and implement additional security measures where possible.

Has this been exploited in the wild?

Yes, this vulnerability has been exploited in the wild as confirmed by multiple sources including CISA and The Hacker News.

Sources

Join the 0Day waitlist →

← Back to all threats