CVE-2026-85706 is a maximum-severity (CVSS 10.0) path traversal vulnerability in GitLab CE/EE's repository commits API that allows unauthenticated remote attackers to read arbitrary files from the GitLab server filesystem. Due to improper path confinement and missing authentication enforcement, a single unauthenticated HTTP request can exfiltrate secrets, credentials, and source code from the server. It is actively exploited in the wild and listed in the CISA KEV catalog.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-12
Added to CISA KEV: 2026-09-11 0 DAY BETWEEN CVE AND KEV
CVE-2026-85706 is a critical-severity (CVSS 10.0) path traversal vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE) [1][6]. The flaw resides in the repository commits API, where improper path confinement and missing authentication enforcement allow unauthenticated, remote attackers to read arbitrary files from the underlying GitLab server [1]. This is a high-consequence vulnerability because it enables direct, unauthorized access to sensitive system files, including configuration files, credentials, and source code, potentially leading to a full system compromise.
CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE. GitLab has remediated an issue that, under certain ... CVE-2026-85706 - Path Traversal issue in repository commits API impacts GitLab CE/EE GitLab has remediated an issue that, under certain conditions, an unauthen…
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
GitLab has issued an emergency patch for CVE-2026-85706, a max-severity path traversal flaw. Self-managed CE/EE instances are at risk — patch and hunt now.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber…
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public disclosure.