GITLAB users have been urged to patch CVE-2026-85706, a maximum-severity path-traversal vulnerability reportedly being probed in the wild. The flaw affects GitLab CE/EE versions 18.7 before 19.1.8, 19.2 before 19.2.6 and 19.3 before 19.3.2. According to GitLab’s advisory, under certain conditions an unauthenticated attacker could read arbitrary files from a GitLab server because of inadequate path confinement and missing authentication enforcement in the repository commits API. GitLab fixed the issue on 10 September 2026.
GitLab had not itself confirmed exploitation, but cybersecurity vendor watchtower said on 11 September that it had detected “in-the-wild probes” targeting the vulnerability. It warned that indiscriminate exploitation could follow and recommended that organisations with publicly accessible, self-hosted GitLab instances patch immediately or remove public access.
To look for possible attacks, watchtower advised reviewing logs for HTTP POST requests to `/api/v4/projects/{id}/repository/commits/` containing `file.path` parameters.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-85706 to its Known Exploited Vulnerabilities catalogue on the same day, giving civilian federal agencies a 15 September deadline to address it and recommending that organisations follow applicable BOD 26-04 guidance for cloud services or discontinue use where mitigations are unavailable.