securityonline.info 11 Sept 2026, 00:14 UTC

GitLab Fixes Critical Path Traversal Flaw Exposing Server Files

GitLab Fixes Critical Path Traversal Flaw Exposing Server Files
CyberSIXT Evidence Panel Source marked as original reporting

GITLAB released security updates on 10 September 2026 addressing eighteen vulnerabilities across Community Edition and Enterprise Edition. The most critical flaw is CVE-2026-85706, described as an unauthenticated path traversal in the repository commits endpoint that could allow reading arbitrary files from the GitLab server. The advisory emphasises that self‑managed GitLab installations should be upgraded immediately to one of the patched versions.

The article notes that no CVE data is listed in the source, but CVSS for the CVE-85706 issue is reported as a perfect 10.0, underscoring the severity of unauthenticated access to repository data.

In addition to CVE-2026-85706, the update addresses CVE-2026-87719 (insecure deserialization; CVSS 9.9) and CVE-2026-88765 (memory‑corrupting buffer overflow; CVSS 8.5). The deserialization flaw could let an authenticated user with Duo Chat access obtain Advanced Search instance configurations and credentials through a crafted GraphQL subscription argument, while the buffer overflow arises from importing malformed Git project exports that could enable arbitrary code execution on the host.

Affected versions include all GitLab Community Edition and Enterprise Edition releases prior to 19.1.8, 19.2.6, and 19.3.2 respectively, with GitLab[.]com cloud instances already on remediated software. Administrators are urged to upgrade to versions 19.3.2, 19.2.6, or 19.1.8 and to restrict access to self‑managed portals where feasible during the transition.

View full article

Article by CyberSIXT