Vulnerabilities
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Cyber RTSeptember 15, 20263 min read

GitLab has issued patches for multiple vulnerabilities, including a critical path traversal flaw (CVE-2026-85706, CVSS score: 10.0) in the repository commits API, allowing unauthenticated file access. This flaw affects GitLab CE and EE versions before 19.1.8, 19.2.6, and 19.3.2. Active exploitation began on September 11, 2026. Organizations must apply patches promptly. Another critical issue, CVE-2026-87719, was also patched.
GitLab has issued patches to fix several vulnerabilities, including a critical security flaw identified as CVE-2026-85706, which has been actively exploited shortly after its public disclosure. This vulnerability, with a CVSS score of 10.0, is a path traversal issue in the repository commits API that could enable an unauthenticated user to read arbitrary files from the GitLab server under certain conditions. The flaw arises from improper path confinement and missing authentication enforcement within the API.
The vulnerability affects specific versions of GitLab Community Edition (CE) and Enterprise Edition (EE), namely all versions from 18.7 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2. According to watchTowr, a preemptive exposure management firm, active in-the-wild probes of this vulnerability began on September 11, 2026. The flaw allows external attackers to access log files and GitLab-specific configuration files, potentially exposing credentials, secrets, and other sensitive information.
This incident marks the second critical GitLab vulnerability in recent weeks, following a GraphQL code injection vulnerability (CVE-2026-19478) that was quickly exploited. Jake Knott, head of threat intelligence at watchTowr, highlighted the attractiveness of GitLab to attackers due to the potential unauthorized access to source code, CI/CD secrets, credentials, and the ability to inject code into build pipelines, which can lead to downstream compromises.
In addition to CVE-2026-85706, GitLab has also patched a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) in versions 19.3.2, 19.2.6, and 19.1.8. This vulnerability could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials by exploiting a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.
Organizations using self-managed GitLab instances exposed to the internet are urged to apply the patches immediately or restrict public access if not necessary. Knott warned that the transition to mass exploitation of this vulnerability could happen soon, and defenders have limited time to respond. He also advised organizations to review log files for specific HTTP POST requests that may indicate exploitation attempts.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the active exploitation of CVE-2026-85706 by adding it to the Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026. Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the patches by September 14, 2026, to mitigate the risk.
In a subsequent update, Knott noted that exploitation efforts have intensified, moving from initial probes to identifying and successfully exploiting vulnerable instances. Over the weekend, threat actors were observed exfiltrating sensitive files, including configuration files and system SSH configurations, which could allow them to extract passwords and gain unauthorized access to affected systems under certain conditions.


