GitLab CE/EE repository commits API path traversal (CVE-2026-85706)
Vulnerability
Summary
Hide ▲
Show ▼
CISA added CVE-2026-85706 to its actively exploited catalog after GitLab CE/EE servers were probed and attacked, increasing the risk of credential and secret disclosure. The flaw is a path traversal problem in the repository commits API caused by missing authentication enforcement and improper path confinement. GitLab released fixes in 19.3.2, 19.2.6, and 19.1 and urged customers to patch immediately.
Related Happenings
CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706
Public Sector Action
H score36
First: 14.09.2026 10:06
Last: 14.09.2026 10:06
Sources 1
How related:
That same day, CISA added the vulnerability to its catalog of actively exploited flaws, giving government agencies three days to secure their systems under Binding Operational Directive (BOD) 26-04.
About this happening:
CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the...
CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706
Public Sector ActionHow related: That same day, CISA added the vulnerability to its catalog of actively exploited flaws, giving government agencies three days to secure their systems under Binding Operational Directive (BOD) 26-04.
About this happening: CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the...
GitLab self-managed installations immediate upgrade advisory
Advisory/Mitigation
H score45
First: 11.09.2026 14:15
Last: 11.09.2026 14:15
Sources 1
About this happening:
GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
GitLab self-managed installations immediate upgrade advisory
Advisory/MitigationAbout this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...
GitLab notebook diff authenticated RCE flaw
Vulnerability
H score37
First: 25.07.2026 11:34
Last: 25.07.2026 11:34
Sources 1
About this happening:
A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE...
GitLab notebook diff authenticated RCE flaw
VulnerabilityAbout this happening: A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE...
Timeline
-
14.09.2026 10:06 2 articles · 2h ago
GitLab CE/EE repository commits API path traversal (CVE-2026-85706)
Initial DisclosureGitLab fixed CVE-2026-85706 in CE/EE 19.3.2, 19.2.6, and 19.1, but probes soon appeared against unpatched servers. The flaw lets unauthenticated requests abuse the repository commits API to expose files and secrets.
Show sources
- CISA: Hackers now exploit max severity GitLab flaw in attacks — www.bleepingcomputer.com — 14.09.2026 10:06
- CISA: Hackers now exploit max severity GitLab flaw in attacks — www.bleepingcomputer.com — 14.09.2026 10:06