LIVE · cybersecurity feed
Live wire
cve recordhighexploited in the wildzero day3 of 3 cataloguesexploit reported

CVE-2026-85706

GitLab · Community Edition and Enterprise Edition · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

· Added to CISA KEV
CVSS
Severityhigh
Weakness
EPSS11.1%95.7th percentile
Exploited3 KEV sources
Ransomware useUnknown
Federal fix dueSep 14, 2026
patch window

Called exploited 1 days before disclosure.

Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.

The life of this vulnerability

  1. CVE reserved
  2. CVE published8d
  3. First KEV listing1d
  4. Last sighting3d

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources3 of 3
Listings differ by0 d
Strongest claimconfirmed

3 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

3 public reports collected from VulnCheck and CIRCL, first on Sep 11, 2026. Each links to its original source. We have not verified them.

Description

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

Required action (CISA)

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-85706

CVE-2026-85706

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

CVE-2026-85706

GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request […]

CVE-2026-85706critical

Critical GitLab Vulnerability Exploited in Internet-Wide Probes

GitLab has released emergency patches for two high-severity vulnerabilities, including one with a critical CVSS score of 10.0 that allows unauthenticated attackers to read any file on a server. A second vulnerability, rated 9.9, enables authenticated users to potentially access sensitive settings and passwords. Security researchers have already observed internet-wide probes targeting the critical file-reading flaw, urging self-managed GitLab users to update immediately.