InfoQSergio De Simone2 min readintermediate
GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration
Summary
CVE-2026-85706 is a critical path-traversal vulnerability in self-managed GitLab CE/EE, allowing unauthenticated attackers to read arbitrary files. It affects versions 18.7-19.3.1 and is under active exploitation, requiring only one public project on the instance.
- CVE-2026-85706 is a critical (CVSS 10.0) path-traversal flaw in GitLab CE/EE, allowing unauthenticated arbitrary file reads.
- It affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1.
- Exploitation requires only one public project on the GitLab instance and targets the repository commits API.
- Beyond patching, rotate all deploy tokens, CI variables, and SSH keys, then check for compromised packages/images.
GitLab administrators and security teams must immediately patch affected instances and perform post-exploitation checks to prevent further system compromise due to active exploitation.
7/10




