DIRAS TAKE
Urgent — CISA listed this vulnerability in the Known Exploited Vulnerabilities catalog with a firm remediation timeline, so immediately apply vendor fixes or compensating controls for internet-facing GitLab servers.
What is CVE-2026-85706?
An unauthenticated remote attacker can exploit a path traversal weakness in GitLab’s repository commits API to retrieve files that the GitLab server can access. CVE-2026-85706 impacts GitLab Community and Enterprise releases 18.7 up to but not including 18.11.12, and several 19.x releases before 19.0.9, 19.1.8, 19.2.6, and 19.3.2. The issue requires only network reachability to the affected GitLab instance and no valid user credentials, enabling disclosure of sensitive server-side files. The weakness is classified as CWE-22 (Path Traversal).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Which versions of GitLab Community Edition and Enterprise Edition are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 18.x | 18.7 – before 18.11.12 | 18.11.12 |
| 19.x | 19.0 – before 19.0.9 | 19.0.9 |
| 19.x | 19.1 – before 19.1.8 | 19.1.8 |
| 19.x | 19.2 – before 19.2.6 | 19.2.6 |
| 19.x | 19.3 – before 19.3.2 | 19.3.2 |
Is CVE-2026-85706 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-11, and U.S. federal agencies were required to remediate it by 2026-09-14.
How to fix CVE-2026-85706
- Upgrade GitLab to a fixed release: 18.11.12, 19.0.9, 19.1.8, 19.2.6, or 19.3.2.
- If unable to upgrade immediately, block or restrict access to the repository commits API from untrusted networks.
- Follow GitLab’s published mitigation guidance and adjust server permissions to limit file exposure.
- Inspect access logs for anomalous commits API requests and unauthorized file retrievals.
Frequently asked questions
Is CVE-2026-85706 being actively exploited?
CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on 2026-09-11, requiring federal remediation by 2026-09-14; public exploit code is also available.
Which GitLab versions are affected by CVE-2026-85706?
GitLab Community Edition and Enterprise Edition releases 18.7 through before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.
Is there a patch for CVE-2026-85706?
Yes. Fixed releases include 18.11.12, 19.0.9, 19.1.8, 19.2.6, and 19.3.2; upgrade to one of these versions.
Does CVE-2026-85706 require authentication?
No. The vulnerability permits unauthenticated access to read files via the repository commits API on a reachable GitLab instance.
References
- nvd.nist.gov/vuln/detail/CVE-2026-85706
- cve.org/CVERecord?id=CVE-2026-85706
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706
- gitlab.com/gitlab-org/gitlab/-/work_items/627748
- hackerone.com/reports/3909881
- All GitLab CVEs on CVE Radar
- CVEs published in September 2026