Executive Summary
GitLab has issued an urgent advisory for a critical path traversal vulnerability, CVE-2026-85706 (CVSS 10.0), affecting both Community and Enterprise editions. The flaw allows unauthenticated attackers to read arbitrary files from the server, including logs and configuration files that contain secrets, tokens, and credentials. CISA has already added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog following reports of in-the-wild probes and exploitation shortly after disclosure.
Technically, the issue stems from improper path confinement and a lack of authentication enforcement in the repository commits API. A secondary critical flaw, CVE-2026-87719 (CVSS 9.9), was also patched, which involves insecure deserialization in GraphQL subscriptions that could lead to information disclosure. The urgency is high as GitLab is a primary target for attackers seeking to compromise CI/CD pipelines and downstream software supply chains.
Organizations using self-managed GitLab instances must upgrade immediately to versions 19.3.2, 19.2.6, or 19.1.8. GitLab.com and Dedicated customers are reported as protected, but all self-managed installations exposed to the internet are at extreme risk of mass exploitation.
Key Details
Threat Name
CVE-2026-85706
Affects
GitLab CE, GitLab EE, GitLab, GitLab CE 18.7 before 19.1.8, GitLab EE 18.7 before 19.1.8, GitLab CE 19.2 before 19.2.6, GitLab EE 19.3 before 19.3.2, GitLab Enterprise Edition (EE), GitLab Community Edition (CE) versions 19.3.2, 19.2.6, 19.1, GitLab Enterprise Edition (EE) versions 19.3.2, 19.2.6, 19.1
Adversary
—
Malware/Tools
EtherHiding, GrayRabbit
