CVE-2026-85706 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 91.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2026-09-14.
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
| EPSS | 91.43% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2026-09-14 |
| Public exploit | none known |
| Published | 2026-09-12 |
| Last modified | 2026-09-24 |
CISA KEV
| Name | GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability |
|---|---|
| Added | 2026-09-11 |
| Due | 2026-09-14 |
| Vendor / product | GitLab / Community Edition and Enterprise Edition |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| gitlab | gitlab |
References
→ the Explorer · watch your stack · NVD