Critical GitLab vulnerability under active exploitation allows unauthenticated file reads

CVE-2026-85706 carries a perfect CVSS score of 10.0 and is already being probed in the wild

By LineZotpaper
Published
Read Time2 min
A critical path-traversal vulnerability in self-managed GitLab CE/EE, designated CVE-2026-85706, is being actively exploited by attackers who can read arbitrary files from the server without authentication. The flaw, which affects multiple version ranges and was patched on September 11, has been added to CISA's Known Exploited Vulnerabilities catalog after security firm watchTowr observed in-the-wild probes within hours of disclosure.

The vulnerability, reported by researcher Mohamed Abdelaiz (S3ntago), affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. It receives a CVSS score of 10.0, the highest possible severity, because it requires no authentication and only that the targeted GitLab instance have at least one public project.

According to the advisory, "under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API." Exploitation could allow attackers to steal secrets, configuration details, and deploy tokens, potentially compromising CI/CD pipelines and gaining access to other connected systems.

GitLab released a patch on September 11. Within hours, watchTowr reported observing active probes. The US Cybersecurity and Infrastructure Security Agency (CISA) subsequently added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, signaling that government agencies must patch promptly.

Cybersecurity executive Christopher Houser warned that patching alone is insufficient. "It doesn't revoke the deploy tokens, CI variables, and SSH keys an attacker already copied," he said. "Rotate those, then check which packages and images your builds pulled while the old credentials were still valid."

watchTowr recommends defenders hunt through logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.path parameters to detect exploitation attempts.

§

Analysis

Why This Matters

  • The vulnerability allows unauthenticated, remote file read on self-managed GitLab instances, which are widely used by organisations to host source code and CI/CD pipelines.
  • Stolen credentials (deploy tokens, SSH keys, CI variables) can enable lateral movement into production systems, supply chain attacks, or further compromise.
  • With active exploitation confirmed and CISA adding the flaw to its KEV catalog, organisations that have not patched face immediate risk.

Background

GitLab is a popular DevOps platform available both as a cloud service and as self-managed installations (GitLab CE/EE). Self-managed instances are maintained by organisations themselves, making timely patching critical. Path-traversal vulnerabilities allow attackers to break out of intended directory restrictions and read files outside the application's scope. CVE-2026-85706 is the latest in a series of critical GitLab bugs, but its combination of a perfect CVSS score, ease of exploitation, and confirmed in-the-wild activity makes it unusually urgent.

Key Perspectives

Security researchers and patch developers: The flaw was responsibly disclosed by Mohamed Abdelaiz and patched within days, but the rapid exploitation window shows the difficulty of protecting against zero-day attacks even after disclosure. Affected organisations: IT teams must not only apply the September 11 patch but also rotate any credentials that may have been exposed, a process that can be time-consuming across large deployments. Attackers: The vulnerability provides a direct path to steal secrets from high-value targets. Public projects are the only precondition, which is common on many GitLab instances.

What to Watch

  • Whether CISA's KEV listing triggers mandatory patching deadlines for US federal agencies and their contractors.
  • Reports of mass scanning for exposed self-managed GitLab instances with public projects.
  • Evidence of credential reuse from victims' stolen tokens being used to attack downstream systems or supply chains.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.