GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Key Points:
- GitLab has released urgent security patches to fix multiple vulnerabilities, including a critical path traversal flaw (CVE-2026-85706, CVSS 10.0) in the repository commits API that allows unauthenticated users to read arbitrary files on affected servers.
- The vulnerability affects GitLab Community and Enterprise Editions in versions from 18.7 up to 19.1.8, 19.2 up to 19.2.6, and 19.3 up to 19.3.2, with active exploitation attempts detected since September 11, 2026.
- Another critical issue patched is an insecure deserialization bug (CVE-2026-87719, CVSS 9.9) in GitLab EE that could expose sensitive credentials via a specially crafted GraphQL subscription argument.
- Security experts warn that unauthorized access to GitLab servers could lead to theft of source code, credentials, CI/CD secrets, and potential code injection into build pipelines, emphasizing the urgency for organizations to apply patches or restrict public access immediately.
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of CVE-2026-85706 and mandated federal agencies to implement fixes by September 14, 2026, highlighting the high risk posed by this vulnerability.