Critical GitLab vulnerability CVE-2026-85706 allows unauthenticated file reads
A critical vulnerability, CVE-2026-85706, allows unauthenticated attackers to read files on unpatched GitLab servers. The flaw is a path traversal issue in GitLab's repository commits API that was fixed in multiple versions released in September 2026. It is listed as actively exploited in CISA's Known Exploited Vulnerabilities catalog, heightening its priority. The vulnerability is particularly dangerous because configuration files often contain credentials and keys that could enable further attacks. Over 1.3 million GitLab instances were indexed online as potential targets.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in