Improper Path Confinement in GitLab CE/EE Affecting User Access
CVE-2026-85706

10CRITICAL

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
12 September 2026

Badges

🔥 Trending now🥇 Trended No. 1📈 Trended📈 Score: 28,300👾 Exploit Exists🟡 Public PoC🟣 EPSS 92%🦅 CISA Reported📰 News Worthy

What is CVE-2026-85706?

CVE-2026-85706 is a significant vulnerability found in GitLab Community Edition (CE) and Enterprise Edition (EE) that affects multiple versions released prior to specific patch updates. GitLab, a widely used platform for version control and collaborative software development, facilitates developers in managing their code repositories and automating workflows. The vulnerability arises from improper path confinement and inadequate authentication enforcement within the repository commits API. Under certain conditions, this flaw allows unauthenticated users to access and read arbitrary files from the GitLab server. The implications of this vulnerability are serious, as unauthorized access to sensitive code components or configuration files can lead to data leaks and compromise the security of an organization's software development lifecycle.

Potential Impact of CVE-2026-85706

  1. Unauthorized Data Exposure: The vulnerability could enable malicious actors to access sensitive information stored within GitLab repositories, including proprietary code, confidential documents, and user credentials, leading to potential data breaches.

  2. Increased Attack Surface: With the ability to read arbitrary files, attackers can gather intelligence on the target organization's infrastructure and practices, facilitating further attacks, including targeted phishing campaigns or social engineering attempts.

  3. Reputation Damage and Compliance Risks: Exploitation of this vulnerability could result in significant reputational harm to affected organizations, especially if sensitive data is leaked or misused. Furthermore, this could pose compliance issues with regulations requiring the protection of sensitive information, escalating potential legal liabilities.

CISA has reported CVE-2026-85706

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-85706 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

GitLab 18.7 < 18.11.12

GitLab 19.0 < 19.0.9

GitLab 19.1 < 19.1.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.

1 day ago

(TLP CLEAR) Weekly Vulnerabilities to Prioritize – September 17, 2026 - WaterISAC

The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical...

2 weeks ago

CISA Warns of Active Exploitation of Critical GitLab Flaw

CISA warns attackers are exploiting a critical GitLab flaw that exposes server files, credentials and development pipelines. Learn how to respond.

3 weeks ago

References

EPSS Score

92% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🥇

    Vulnerability reached the number 1 worldwide trending spot

  • 🟡

    Public PoC available

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • Vulnerability published

  • 🦅

    CISA Reported

  • 📰

    First article discovered by Securityweek

  • Vulnerability Reserved

Credit

Thanks [s3ntago](https://hackerone.com/s3ntago) for reporting this vulnerability through our HackerOne bug bounty program
.