Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

GitLab Patches Critical File-Read Flaw as Exploitation Attempts Begin

Published 12 September 2026

GitLab has issued an emergency security update to patch a critical vulnerability that allows unauthenticated attackers to read arbitrary files from self-managed servers, with security researchers observing active exploitation attempts within a day of the flaw's public disclosure. The vulnerability, tracked as CVE-2026-85706 and carrying a maximum CVSS score of 10.0, resides in the repository commits API. GitLab stated the issue stems from "improper path confinement and missing authentication enforcement," enabling unauthenticated network-based reading of credentials and sensitive information under certain conditions. The flaw affects self-managed GitLab Community Edition and Enterprise Edition versions from 18.7 prior to 19.1.8, the 19.2 series prior to 19.2.6, and the 19.3 series prior to 19.3.2. Security firm watchTowr reported observing active scanning and exploitation attempts targeting CVE-2026-85706 starting at 0600 UTC on September 11, 2026, just one day after GitLab released patches.

0:00 / 0:00