SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-85706

CRITICAL · CVSS 10 EPSS 1.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

GitLab versions prior to 19.1.8, 19.2.6, and 19.3.2 are vulnerable to a critical flaw that allows unauthenticated users to read arbitrary files from the server, stemming from improper path confinement and lack of authentication enforcement in the repository commits API. This vulnerability poses a significant risk to sensitive data exposure, making it imperative for all GitLab users, particularly those managing sensitive repositories, to prioritize immediate updates to the latest versions. Organizations relying on GitLab for version control should act swiftly to mitigate potential data breaches.

CVE
CVE-2026-85706
Severity
CRITICAL
CVSS
10
EPSS
1.16%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.