• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-85706: pre-auth path traversal in GitLab Community Edition and Enterprise Edition

An unauthenticated remote attacker can exploit a path traversal weakness in GitLab’s repository commits API to retrieve files that the GitLab server can access. CVE-2026-85706 impacts GitLab Community and Enterprise releases 18.7 up to but not including 18.11.12, and several 19.x releases before 19.0.9, 19.1.8, 19.2.6, and 19.3.2. The issue requires only network reachability to the affected GitLab instance and no valid user credentials, enabling disclosure of sensitive server-side files.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.91425
CWE
CWE-22
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA listed this vulnerability in the Known Exploited Vulnerabilities catalog with a firm remediation timeline, so immediately apply vendor fixes or compensating controls for internet-facing GitLab servers.

What is CVE-2026-85706?

An unauthenticated remote attacker can exploit a path traversal weakness in GitLab’s repository commits API to retrieve files that the GitLab server can access. CVE-2026-85706 impacts GitLab Community and Enterprise releases 18.7 up to but not including 18.11.12, and several 19.x releases before 19.0.9, 19.1.8, 19.2.6, and 19.3.2. The issue requires only network reachability to the affected GitLab instance and no valid user credentials, enabling disclosure of sensitive server-side files. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of GitLab Community Edition and Enterprise Edition are affected?

BRANCHAFFECTEDFIXED
18.x18.7 – before 18.11.1218.11.12
19.x19.0 – before 19.0.919.0.9
19.x19.1 – before 19.1.819.1.8
19.x19.2 – before 19.2.619.2.6
19.x19.3 – before 19.3.219.3.2

Is CVE-2026-85706 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-11, and U.S. federal agencies were required to remediate it by 2026-09-14.

How to fix CVE-2026-85706

  1. Upgrade GitLab to a fixed release: 18.11.12, 19.0.9, 19.1.8, 19.2.6, or 19.3.2.
  2. If unable to upgrade immediately, block or restrict access to the repository commits API from untrusted networks.
  3. Follow GitLab’s published mitigation guidance and adjust server permissions to limit file exposure.
  4. Inspect access logs for anomalous commits API requests and unauthorized file retrievals.

Frequently asked questions

Is CVE-2026-85706 being actively exploited?

CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on 2026-09-11, requiring federal remediation by 2026-09-14; public exploit code is also available.

Which GitLab versions are affected by CVE-2026-85706?

GitLab Community Edition and Enterprise Edition releases 18.7 through before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.

Is there a patch for CVE-2026-85706?

Yes. Fixed releases include 18.11.12, 19.0.9, 19.1.8, 19.2.6, and 19.3.2; upgrade to one of these versions.

Does CVE-2026-85706 require authentication?

No. The vulnerability permits unauthenticated access to read files via the repository commits API on a reachable GitLab instance.

References