Executive Summary
GitLab has issued emergency patches for two critical vulnerabilities affecting self-managed Community and Enterprise Edition instances. The most severe, CVE-2026-85706 (CVSS 10.0), is a path traversal flaw that allows unauthenticated attackers to read arbitrary files from the server, including configuration files and credentials. A second critical issue, CVE-2026-87719 (CVSS 9.9), involves insecure deserialization via GraphQL that could lead to sensitive information disclosure.
Technical analysis indicates that CVE-2026-85706 is already being probed in the wild within hours of disclosure. Exploitation requires at least one public project to exist on the instance. These flaws follow a trend of high-severity GitLab vulnerabilities, such as CVE-2026-19478, being rapidly targeted by threat actors to gain access to proprietary source code and CI/CD pipelines.
Unauthorized access to GitLab instances pose a significant risk to the software supply chain, potentially allowing attackers to steal secrets or poison downstream build processes. Organizations using self-managed GitLab versions 18.7 through 19.3 must upgrade to versions 19.3.2, 19.2.6, or 19.1.8 immediately to mitigate these risks.
