All news & advisories
Actively exploited

CVE-2026-85706: Actively Exploited Vulnerability

CVE-2026-85706 CVSS 10 CISA KEV · actively exploited
Who it affects
See the summary below.
What to do
Patch immediately — prioritise internet-facing systems.

CVE-2026-85706 - GitLab Arbitrary File Read

Severity: CRITICAL (CVSS 10.0)
KEV Status: Actively Exploited

Affected Versions

  • GitLab CE/EE 18.7 – 19.1.7
  • GitLab CE/EE 19.2.0 – 19.2.5
  • GitLab CE/EE 19.3.0 – 19.3.1

Vulnerability Description

An unauthenticated user can read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Remediation

Upgrade to:

  • GitLab 19.1.8 or later
  • GitLab 19.2.6 or later
  • GitLab 19.3.2 or later

References

Data as of September 12, 2026. Sources: nvd.nist.gov, gitlab.com, hackerone.com, cisa.gov. Figures are pulled from public vendor and security data and refreshed automatically.
Back to all news & advisories