Maximum Severity GitLab Flaw Puts Supply Chains at Risk
Reported exploitedGitLab Community EditionGitLab Enterprise EditionOur summary
Threat actors are actively exploiting CVE-2026-85706, a critical path traversal vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on September 14, 2026. This flaw, which carries a CVSS score of 10.0, permits unauthenticated users to read arbitrary files from self-hosted instances of GitLab Community Edition and Enterprise Edition. Researchers at watchTowr confirmed that attackers have escalated probes into full exploitation, successfully exfiltrating configuration and SSH files to potentially steal credentials and access development environments.
To mitigate this risk, organizations must update their self-hosted GitLab instances to versions 19.3.2, 19.2.6, or 19.1.8 immediately. If updates are not possible, administrators should restrict public access to their instances and audit repository commits API logs for unauthenticated requests.
Dark Reading publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.