Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [incident, global] ยท confidence: high ยท severity: critical ยท affected_sectors: [global] ยท au_impact: true

GitLab has released patches for multiple flaws including CVE-2026-85706, a maximum-severity path-traversal vulnerability in the repository commits API that allows an unauthenticated user to read arbitrary files from the GitLab server under certain conditions, arising from improper path confinement and missing authentication enforcement. Affected versions are all Community and Enterprise Edition releases from 18.7 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2. The security firm watchTowr recorded active in-the-wild probes from 06:00 UTC on 11 September โ€” within hours of public disclosure โ€” and warned that the transition to indiscriminate mass exploitation is likely to follow, given that the flaw needs no authentication and remote file reads from a repository server expose CI/CD configuration, tokens and source. Recommended detections are internet-facing GitLab instances patched or access-restricted, and log review for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing a file.Path parameter. The story fits the week's clearest pattern precisely: a build-pipeline component with a credential-rich file store and a trivially reachable attack surface, where the time from disclosure to scanning is measured in hours and the time from scanning to mass exploitation in days.

Attribute Detail
Sector Global (Macro)
Date 2026-09-12
Source CyberScoop
Reliability Tier 2
CVEs CVE-2026-85706