GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Overview
GitLab disclosed a severe vulnerability, CVE-2026-85706, on September 10, 2026, which has a maximum severity score of 10.0. This path traversal flaw affects the repository commits API, allowing attackers to read files that should remain inaccessible without authentication. Within just 24 hours of the public announcement, malicious actors began exploiting this vulnerability, raising concerns about the security of GitLab instances. Organizations using GitLab should prioritize patching this vulnerability to protect sensitive information from unauthorized access, as attackers can exploit the flaw with a single crafted HTTP request. The rapid exploitation of this vulnerability underscores the need for timely updates and proactive security measures in software development environments.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: GitLab's repository commits API, all versions affected prior to patching.
- Action Required: Users should update to the latest version of GitLab to mitigate this vulnerability.
- Timeline: Disclosed on September 10, 2026
Original Article Summary
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]
Impact
GitLab's repository commits API, all versions affected prior to patching.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Disclosed on September 10, 2026
Remediation
Users should update to the latest version of GitLab to mitigate this vulnerability. Specific patch numbers are not mentioned, but applying the latest software updates is critical.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Exploit, Vulnerability.