Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Max severity GitLab path traversal flaw under active reconnaissance

A maximum-severity path traversal vulnerability (CVE-2026-85706, CVSS 10.0) in GitLab CE/EE allows unauthenticated attackers to read arbitrary server files via a crafted HTTP POST request to the repository commits API, requiring only one public project on the target instance. Affected versions are GitLab CE/EE 18.2.0 through 18.11.10, 19.0.0 through 19.0.7, and 19.1.0 through 19.1.5, requiring an upgrade to versions 18.11.11, 19.0.8, or 19.1.6 respectively. Self-managed instances should upgrade immediately and review logs for suspicious POST requests to `/api/v4/projects/[id]/repository/commits/` containing `file.path` parameters.
Read Full Article →

Vulnerability Management , Patch/Configuration Management Max severity GitLab path traversal flaw under active reconnaissance September 11, 2026 Share By Laura French (Credit: Rafael Henrique – stock.adobe.com) GitLab patched a maximum-severity vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) that is being actively probed in the wild, according to watchTowr . The vulnerability, tracked as CVE-2026-85706 and reported by s3ntago via GitLab’s HackerOne bug bounty program, was patched by GitLab on Thursday in GitLab CE/EE versions 19.1.8, 19.2.6 and 19.3.2. It has a CVSS score of 10.0. “Under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API,” the vulnerability description reads. In a statement provided to SC Media, WatchTowr Head of Threat Intelligence Jake Knott said that active probes for CVE-2026-85706 were detected against watchTowr’s Attacker Eye honeypot network as of 6:00 UTC on Sept.11, indicating rapid reverse engineering of the flaw. WatchTowr also stated that it managed to reproduce the flaw and validate exposure of self-managed GitLab clients . The vulnerability could allow an attacker to read arbitrary files via an unauthenticated HTTP request, with the only requirement being one public project existing on the targeted instance, Knott described. Common sensitive files that could contain credentials, keys and tokens, such as log files, are likely to be targeted, Knott added. “The appeal to attackers of GitLab is obvious, as unauthorized access allows an attacker to gain access to source code, CI/CD secrets , credentials, and the ability to inject code into build pipelines, gaining access or poisoning anything downstream of it, which as we’ve seen throughout the year has been a favorite of attackers,” Knott stated. Operators of self-managed GitLab instances are urged to upgrade to the patched versions immediately, while GitLab Dedicated customers and users of GitLab.com do not need to take action. WatchTowr also recommends self-managed customers review their log files for HTTP POST requests to “/api/v4/projects/[id]/repository/commits/” URIs that contain “file.path” parameters, which could indicate potential exploitation of CVE-2026-85706. GitLab patched another critical vulnerability in GitLab EE on Thursday. Tracked as CVE-2026-87719, with a CVSS score of 9.9, the vulnerability allows an authenticated user with Duo Chat access to use a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup, enabling them to obtain sensitive credentials and Advanced Search instance configurations. GitLab flaw patched another critical flaw, tracked as CVE-2026-19478 , last month, which Knott told SC Media also came under active exploitation shortly after it disclosure. This flaw, which was patched in GitLab CE/EE versions 18.11.11, 19.0.8, 19.1.6 and 19.2.4, could allow an unauthenticated user to remotely modify or delete public project and user data via the GraphQL directive. Laura French Laura French has been a staff reporter for SC Media since 2023. Laura writes daily news stories, contributes to feature stories, covers industry events and edits briefs for the SC Media website. A New Jersey native, Laura graduated from Ramapo College in 2016 and has previously written for Labcompare, FireRescue1, EMS1 and Forensic Magazine. Related Vulnerability Management Check Point patches two critical VPN gateway bugs Steve Zurier September 11, 2026 Check Point fixed two 9.8-severity VPN flaws before any known exploitation in the wild. Vulnerability Management Over 36,000 Plex media servers remain unpatched against security vulnerabilities SC Staff September 9, 2026 The unpatched Plex Media Server instances are running versions 1.43.2 and earlier. Patch/Configuration Management What Microsoft’s largest Patch Tuesday update means to security teams Waseem Ahmed September 9, 2026 September 2026 Patch Tuesday set a record and teams must now shift to risk-based prioritization versus simply finding bugs. Related Events Cybercast State of Vulnerability Management On-Demand Event Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article