peter bassill · operator
$ cve CVE-2026-85706 JSON

CVE-2026-85706 KEV

10.0
CRITICAL · CVSS 3.1 · EPSS 91.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-14.

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS91.43% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2026-09-14
Public exploitnone known
Published2026-09-12
Last modified2026-09-24

CISA KEV

NameGitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Added2026-09-11
Due2026-09-14
Vendor / productGitLab / Community Edition and Enterprise Edition
Ransomware usenone reported

Affected (1)

VendorProduct
gitlabgitlab

References

→ the Explorer  ·  watch your stack  ·  NVD