Improper Path Confinement in GitLab CE/EE Affecting User Access
CVE-2026-85706
Key Information:
Badges
What is CVE-2026-85706?
CVE-2026-85706 is a significant vulnerability found in GitLab Community Edition (CE) and Enterprise Edition (EE) that affects multiple versions released prior to specific patch updates. GitLab, a widely used platform for version control and collaborative software development, facilitates developers in managing their code repositories and automating workflows. The vulnerability arises from improper path confinement and inadequate authentication enforcement within the repository commits API. Under certain conditions, this flaw allows unauthenticated users to access and read arbitrary files from the GitLab server. The implications of this vulnerability are serious, as unauthorized access to sensitive code components or configuration files can lead to data leaks and compromise the security of an organization's software development lifecycle.
Potential Impact of CVE-2026-85706
-
Unauthorized Data Exposure: The vulnerability could enable malicious actors to access sensitive information stored within GitLab repositories, including proprietary code, confidential documents, and user credentials, leading to potential data breaches.
-
Increased Attack Surface: With the ability to read arbitrary files, attackers can gather intelligence on the target organization's infrastructure and practices, facilitating further attacks, including targeted phishing campaigns or social engineering attempts.
-
Reputation Damage and Compliance Risks: Exploitation of this vulnerability could result in significant reputational harm to affected organizations, especially if sensitive data is leaked or misused. Furthermore, this could pose compliance issues with regulations requiring the protection of sensitive information, escalating potential legal liabilities.
Affected Version(s)
GitLab 18.7 < 19.1.8
GitLab 19.2 < 19.2.6
GitLab 19.3 < 19.3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
13 hours ago
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- π
Vulnerability started trending
- πΎ
Exploit known to exist
Vulnerability published
- π°
First article discovered by The Hacker News
Vulnerability Reserved