A Maximum Severity GitLab Flaw Could Turn Your CI/CD Server Into an Attacker’s Treasure Trove
8 Articles
8 Articles
GitLab's Perfect-Score Flaw Exposes Servers to Unauthenticated File Theft as CISA Sounds Alarm
CISA added CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab, to its KEV catalog after confirmed exploitation. The bug lets unauthenticated attackers read arbitrary files via the commits API. Self-managed users must patch versions before 19.1.8, 19.2.6, and 19.3.2 immediately.
A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single HTTP request. The path traversal flaw results from improper confinement and lack of authentication enforcement in GitLab’s repository commits API, the company reported. …
U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited… Read more →
The IT security agency CISA warns of observed attacks on GitLab, ConnectWise ScreenConnect and JFrog Artifactory.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









