Skip to main content
QUIETLYTIC
Vulnerability

GitLab Community Edition Path Traversal (CVE-2026-85706)

CVE-2026-85706 is a maximum-severity CVSS 10.0 path traversal flaw in GitLab CE/EE, added to CISA's KEV catalog on September 11, 2026 as actively exploited.

CVE-2026-85706
Threat Level
CRITICAL
CVSS
10.0
Status
Active Exploitation
Confidence
Medium
Affected Products
GitLab Community Edition, GitLab Enterprise Edition

CVE-2026-85706, a path traversal vulnerability in GitLab Community Edition and Enterprise Edition, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026, confirming active exploitation. NVD scores it CVSS 3.1 base 10.0 — the maximum possible score.

What the vulnerability does

NVD classifies CVE-2026-85706 under CWE-22 (Path Traversal). Per GitLab’s own description in NVD’s data, the flaw affects GitLab CE/EE across three version ranges: 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Under certain conditions, an unauthenticated user could read arbitrary files from the GitLab server, due to improper path confinement combined with missing authentication enforcement specifically in the repository commits API.

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N) shows a network-reachable, low-complexity flaw needing no authentication and no user interaction, with a changed scope (S:C) — meaning a successful exploit can affect resources beyond the vulnerable component itself — and high impact to both confidentiality and integrity, though not availability.

Why it’s on KEV

CISA added CVE-2026-85706 to the KEV catalog on September 11, 2026, two days after GitLab’s own remediation (per NVD’s published date of September 12, though GitLab’s fix predates the KEV listing per the description’s “has remediated” phrasing). Under Binding Operational Directive (BOD) 26-04, CISA’s KEV entry directs affected organizations to Citrix-style guidance generically — apply vendor mitigations and evaluate internet exposure directly, rather than a fixed CISA-set deadline.

What we don’t yet have

As with our other recent KEV advisories, this record currently rests on a single source per field (NVD for CVSS/description/references, CISA KEV for title/vendor/product/mitigation metadata) — no second source has independently corroborated any field yet, so confidence is medium, not high. We also don’t have an EPSS score or exploit-availability classification (proof-of-concept vs. weaponized vs. observed-in-the-wild) beyond the KEV listing itself.

Why this matters

A perfect CVSS 10.0 score reflects the worst-case combination: no authentication required, low attack complexity, and impact that extends beyond the vulnerable component. An unauthenticated arbitrary-file-read in a GitLab instance’s commits API is a direct path to source code, CI/CD secrets, and configuration files — any of which can cascade into a much deeper compromise of downstream infrastructure. Self-hosted GitLab CE/EE instances in the affected version ranges (18.7–19.1.8, 19.2–19.2.6, 19.3–19.3.2) should be prioritized for immediate patching regardless of the KEV listing’s own guidance, given the scope-changed, unauthenticated nature of the flaw.

Frequently Asked Questions

What is CVE-2026-85706? A maximum-severity (CVSS 10.0) path traversal vulnerability in GitLab CE/EE affecting versions 18.7 through 19.1.8, 19.2 through 19.2.6, and 19.3 through 19.3.2, allowing an unauthenticated user to read arbitrary server files via the repository commits API.

Is CVE-2026-85706 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026, which CISA only does when it has evidence of active exploitation.

What should GitLab self-hosted administrators do? Upgrade to a patched version (19.1.8, 19.2.6, or 19.3.2 or later, per GitLab’s own remediation) immediately, given the unauthenticated, maximum-severity nature of this flaw.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 15, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools