type: cve ยท created: 2026-09-12 ยท updated: 2026-09-12 ยท tags: [cve, path-traversal, devops, unauthenticated, exposure] ยท confidence: medium ยท severity: critical ยท affected_sectors: [global] ยท au_impact: false
GitLab has released patches for multiple flaws including CVE-2026-85706, a maximum-severity path-traversal vulnerability in the repository commits API that allows an unauthenticated user to read arbitrary files from the GitLab server under certain conditions, arising from improper path confinement and missing authentication enforcement.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-85706 |
| CVSS | 10.0 |
| Vendor / product | GitLab โ GitLab Community Edition / Enterprise Edition |
| Reported | 2026-09-12 |