๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Summary
GitLab Community Edition and Enterprise Edition has a path traversal vulnerability (a flaw that lets attackers access files outside intended directories) in its repository commits API that allows unauthenticated users to read arbitrary files on the system. The vulnerability exists because the API fails to properly restrict file access paths and does not verify that users are logged in before granting access. This vulnerability is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations according to vendor instructions and CISA's BOD 26-04 guidance (https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk). Refer to the GitLab patch release at https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/ for specific patches. If mitigations are unavailable, discontinue use of the product. Due date for patching: 2026-09-14.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
September 10, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85706
First tracked: September 11, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%