GitLab urges users to patch max severity path traversal flaw
9 Articles
9 Articles
GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]
One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours
A single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint is sufficient to bypass security controls and read arbitrary files from a GitLab server. This path traversal vulnerability, designated CVE-2026-85706, carries a CVSS score of 10.0. It stems from a failure in path confinement combined with a complete lack of authentication enforcement. To trigger the exploit, […]
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Adds One Known Exploited Vulnerability to Catalog awallace Sep 11, 2026 Release DateSeptember 11, 2026 DescriptionCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal VulnerabilityThis type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant r…
GitLab Vulnerability Exploited One Day After Disclosure
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public disclosure.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









