GitLab File-Read Flaw CVE-2026-85706: Critical Threat Alert
- Severity
- HIGH
- Affected component
- gitlab (other)
- Patched version
- Not yet available
GitLab Community Edition and Enterprise Edition have a critical path traversal vulnerability that allows unauthenticated users to read arbitrary files. This is due to improper path confinement and missing authentication enforcement in the repository commits API.
What happened
The vulnerability, tracked as CVE-2026-85706, was first flagged on September 11, 2026, and confirmed on the same day. It has been exploited in the wild, as reported by multiple independent sources including CISA and The Hacker News. The flaw allows attackers to read sensitive files on the server, potentially leading to data breaches and further exploitation.
The vulnerability affects GitLab Community Edition and Enterprise Edition, but no authoritative version range has been published yet. Users are advised to upgrade to the latest version of GitLab to mitigate this risk.
What to do about it
- Upgrade to the latest version of GitLab Community Edition and Enterprise Edition.
- Monitor the official GitLab security advisories and update logs for any new information or patches.
- Review your GitLab configurations to ensure that only necessary files and directories are accessible.
- Implement additional security measures such as network segmentation and access controls to limit the impact of potential exploits.
- Stay informed about the latest security updates and best practices for GitLab and similar platforms.
How 0Day would have caught this
gitlab is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using GitLab Community Edition or Enterprise Edition, you may be affected. No specific version range has been published yet, so it is recommended to upgrade to the latest version as a precaution.
What should I do right now?
Upgrade to the latest version of GitLab Community Edition and Enterprise Edition. Monitor official security advisories for updates and implement additional security measures where possible.
Has this been exploited in the wild?
Yes, this vulnerability has been exploited in the wild as confirmed by multiple sources including CISA and The Hacker News.
Sources
- NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions
- [GHSA-2h44-8472-frjj] @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
- [GHSA-vmp7-252j-cwp7] @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
- [GHSA-2h44-8472-frjj] @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
- CISA: Hackers now exploit max severity GitLab flaw in attacks
- [CISA KEV] CVE-2026-85706 — GitLab Community Edition and Enterprise Edition
- Maximum Severity GitLab Flaw Puts Supply Chains at Risk