Critical GitLab Path Traversal and Deserialization Vulnerabilities
Score: 6/10

Critical GitLab Path Traversal and Deserialization Vulnerabilities

GitLab released urgent patches for a maximum-severity path traversal vulnerability (CVE-2026-85706) and a critical insecure deserialization flaw (CVE-2026-87719) currently seeing in-the-wild probes.

Executive Summary

GitLab has issued emergency patches for two critical vulnerabilities affecting self-managed Community and Enterprise Edition instances. The most severe, CVE-2026-85706 (CVSS 10.0), is a path traversal flaw that allows unauthenticated attackers to read arbitrary files from the server, including configuration files and credentials. A second critical issue, CVE-2026-87719 (CVSS 9.9), involves insecure deserialization via GraphQL that could lead to sensitive information disclosure.

Technical analysis indicates that CVE-2026-85706 is already being probed in the wild within hours of disclosure. Exploitation requires at least one public project to exist on the instance. These flaws follow a trend of high-severity GitLab vulnerabilities, such as CVE-2026-19478, being rapidly targeted by threat actors to gain access to proprietary source code and CI/CD pipelines.

Unauthorized access to GitLab instances pose a significant risk to the software supply chain, potentially allowing attackers to steal secrets or poison downstream build processes. Organizations using self-managed GitLab versions 18.7 through 19.3 must upgrade to versions 19.3.2, 19.2.6, or 19.1.8 immediately to mitigate these risks.

Key Details

Threat Name

CVE-2026-85706

Affects

GitLab CE, GitLab EE, GitLab, GitLab CE 18.7 before 19.1.8, GitLab EE 18.7 before 19.1.8, GitLab CE 19.2 before 19.2.6, GitLab EE 19.3 before 19.3.2, GitLab Enterprise Edition (EE)

Adversary

—

MITRE Techniques

Malware/Tools

EtherHiding

Report Score

6out of 10
Quality Score
Fair
IOC Quality2
TTP Details6
Detection Guidance5
Enterprise Relevance9
Clarity & Structure8
Technical Depth5

Sources