HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Path Traversal in GitLab Repository Commits API (CVE‑2026‑85706) Enables Full File Read

GitLab disclosed CVE‑2026‑85706, a CVSS 10.0 path‑traversal bug that lets unauthenticated actors read arbitrary files via the commits API. The flaw is being exploited in the wild, making rapid patching and log‑based hunting essential for audit‑ready control assurance.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Path Traversal in GitLab Repository Commits API (CVE‑2026‑85706) Enables Full File Read

What It Is – GitLab’s repository commits API contains a path‑traversal flaw (CVE‑2026‑85706) that allows an unauthenticated attacker to read arbitrary files on the server with a single HTTP request.

Exploitability – The vulnerability carries a CVSS 10.0 score and was observed being probed in the wild within 24 hours of public disclosure; CISA has added it to the Known Exploited Vulnerabilities catalog.

Affected Products – All GitLab Community and Enterprise editions from 18.7 < 19.1.8, 19.2 < 19.2.6, and 19.3 < 19.3.2.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous monitoring of API traffic and immutable log collection to prove that no unauthorized file reads have occurred.
  • Highlights the importance of rapid patch management as a control evidence point for audit readiness.
  • Forces organizations to rotate exposed credentials (SSH keys, CI/CD tokens) and retain evidence of rotation for compliance reviews.

Recommended Actions

  1. Apply the GitLab 19.1.8/19.2.6/19.3.2 security patches immediately, or block public access to self‑hosted instances.
  2. Search web server and GitLab logs for POST requests to /api/v4/projects/{id}/repository/commits/ containing a file.path parameter; flag any matches for investigation.
  3. Rotate any credentials that may have been exposed (SSH keys, deploy tokens, CI/CD variables, cloud keys) and retain rotation logs as audit evidence.
  4. Implement a continuous API‑traffic monitoring rule that alerts on anomalous file.path parameters.

Source: Security Affairs – GitLab CVE‑2026‑85706

📰 Original Source
https://securityaffairs.com/198945/hacking/gitlab-cve-2026-85706-one-http-request-no-authentication-full-file-read-exploited-within-24-hours.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →