Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [cve, path-traversal, devops, unauthenticated, exposure] ยท confidence: medium ยท severity: critical ยท affected_sectors: [global] ยท au_impact: false

GitLab has released patches for multiple flaws including CVE-2026-85706, a maximum-severity path-traversal vulnerability in the repository commits API that allows an unauthenticated user to read arbitrary files from the GitLab server under certain conditions, arising from improper path confinement and missing authentication enforcement.

Attribute Detail
CVE CVE-2026-85706
CVSS 10.0
Vendor / product GitLab โ€” GitLab Community Edition / Enterprise Edition
Reported 2026-09-12