GitLab Patched Critical Path-Traversal Flaw
The vulnerability allowed unauthenticated attackers to read arbitrary files from server instances.
Updated on Oct. 3, 2026 in Cybersecurity

Live Poll
Do you trust that major software platforms sufficiently protect your data from unauthenticated access?
On September 11, 2026, GitLab released security patches for a critical path-traversal vulnerability, designated CVE-2026-85706. The security flaw allowed unauthenticated remote attackers to access arbitrary files on servers hosting at least one public project.
Why it matters
The vulnerability posed a significant security risk, leading CISA to include it in its Known Exploited Vulnerabilities Catalog due to confirmed instances of unauthenticated data exfiltration. Attackers successfully leveraged the flaw to gain unauthorized access by exploiting the repository commits API.
The vulnerability is assigned a critical CVSS score of 10.0, indicating the highest possible level of severity. It affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1.
The players
GitLab
This is a web-based DevOps platform that provides a complete software development lifecycle, including git repository management and continuous integration.
CISA
The Cybersecurity and Infrastructure Security Agency is a United States federal agency tasked with protecting the nation's critical infrastructure from physical and cyber threats.
Mohamed Abdelaiz
He is the security researcher who identified and reported the critical vulnerability to the platform developers.
The details
The flaw stems from improper path confinement and missing authentication enforcement within the repository commits API. GitLab addressed the issue by releasing patches on September 11, 2026, and backporting the fixes to versions 19.0.9 and 18.11.12.
Timeline
September 11, 2026: GitLab released security patches to address CVE-2026-85706.
The Tech Race
The addition of CVE-2026-85706 to the CISA Known Exploited Vulnerabilities Catalog highlights the urgent requirement for organizations to prioritize patching, as this catalog serves as an authoritative list of security threats that have been weaponized against systems. This underscores the constant evolution of exploit methods targeting common API functions and the race to secure enterprise software.
Users and administrators must ensure their GitLab instances are updated to the patched versions to prevent unauthorized file access. Organizations can identify potential exploitation attempts by reviewing server log files for suspicious HTTP POST requests associated with the repository commits API.
The takeaway
Maintaining up-to-date software is the primary defense against critical vulnerabilities that allow for remote data exfiltration. System administrators should treat CISA-cataloged vulnerabilities as high-priority security tasks to mitigate the risk of unauthenticated access.
Further reading
For more information on securing development platforms, visit Cybersecurity.
Source note: This article includes information reported by InfoQ.
Live Poll
Do you trust that major software platforms sufficiently protect your data from unauthenticated access?







