CVE-2026-85706, a path traversal vulnerability in GitLab Community Edition and Enterprise Edition, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 11, 2026, confirming active exploitation. NVD scores it CVSS 3.1 base 10.0 — the maximum possible score.
What the vulnerability does
NVD classifies CVE-2026-85706 under CWE-22 (Path Traversal). Per GitLab’s own description in NVD’s data, the flaw affects GitLab CE/EE across three version ranges: 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Under certain conditions, an unauthenticated user could read arbitrary files from the GitLab server, due to improper path confinement combined with missing authentication enforcement specifically in the repository commits API.
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N) shows a network-reachable, low-complexity flaw needing no authentication and no user interaction, with a changed scope (S:C) — meaning a successful exploit can affect resources beyond the vulnerable component itself — and high impact to both confidentiality and integrity, though not availability.
Why it’s on KEV
CISA added CVE-2026-85706 to the KEV catalog on September 11, 2026, two days after GitLab’s own remediation (per NVD’s published date of September 12, though GitLab’s fix predates the KEV listing per the description’s “has remediated” phrasing). Under Binding Operational Directive (BOD) 26-04, CISA’s KEV entry directs affected organizations to Citrix-style guidance generically — apply vendor mitigations and evaluate internet exposure directly, rather than a fixed CISA-set deadline.
What we don’t yet have
As with our other recent KEV advisories, this record currently rests on a single source per field (NVD for CVSS/description/references, CISA KEV for title/vendor/product/mitigation metadata) — no second source has independently corroborated any field yet, so confidence is medium, not high. We also don’t have an EPSS score or exploit-availability classification (proof-of-concept vs. weaponized vs. observed-in-the-wild) beyond the KEV listing itself.
Why this matters
A perfect CVSS 10.0 score reflects the worst-case combination: no authentication required, low attack complexity, and impact that extends beyond the vulnerable component. An unauthenticated arbitrary-file-read in a GitLab instance’s commits API is a direct path to source code, CI/CD secrets, and configuration files — any of which can cascade into a much deeper compromise of downstream infrastructure. Self-hosted GitLab CE/EE instances in the affected version ranges (18.7–19.1.8, 19.2–19.2.6, 19.3–19.3.2) should be prioritized for immediate patching regardless of the KEV listing’s own guidance, given the scope-changed, unauthenticated nature of the flaw.
Frequently Asked Questions
What is CVE-2026-85706? A maximum-severity (CVSS 10.0) path traversal vulnerability in GitLab CE/EE affecting versions 18.7 through 19.1.8, 19.2 through 19.2.6, and 19.3 through 19.3.2, allowing an unauthenticated user to read arbitrary server files via the repository commits API.
Is CVE-2026-85706 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 11, 2026, which CISA only does when it has evidence of active exploitation.
What should GitLab self-hosted administrators do? Upgrade to a patched version (19.1.8, 19.2.6, or 19.3.2 or later, per GitLab’s own remediation) immediately, given the unauthenticated, maximum-severity nature of this flaw.
Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 15, 2026. See more vulnerability intelligence.