- Description
- GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
- Source
- cve@gitlab.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 5.8
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- Severity
- CRITICAL
- cve@gitlab.com
- CWE-22
- Hype score
- Not currently trending
GitLab parchea CVE-2026-85706 (CVSS 10): con un solo proyecto público, un atacante sin autenticación lee logs y configs con credenciales. https://t.co/vmJdRaG1YW
@NeoteoCom
12 Sept 2026
49 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに3件と1件の脆弱性を追加。 - JFrog Artifactory: CVE-2026-42016, CVE-2026-42018 - ConnectWise ScreenConnect: CVE-2026-84869 - GitLab: CVE-2026-85706
@__kokumoto
12 Sept 2026
515 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
GitLab patched CVE-2026-85706, a max-severity path traversal flaw that could expose credentials and sensitive data. watchTowr also reported early probing against exposed GitLab systems. #GitLab #CVE-2026-85706 #watchTowr https://t.co/3zARFgSt5B
@TweetThreatNews
11 Sept 2026
156 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 BREAKING: GITLAB CVSS 10.0 VULNERABILITY 🚨 GitLab has patched CVE-2026-85706, a MAXIMUM-SEVERITY CVSS 10.0 path traversal vulnerability that can allow an unauthenticated attacker to read arbitrary files from vulnerable self-managed GitLab servers. Read the full GitLab h
@thecybersecguru
11 Sept 2026
405 Impressions
2 Retweets
5 Likes
2 Bookmarks
0 Replies
0 Quotes