Cyber Security News

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.

The issue affects GitLab Community Edition and Enterprise Edition deployments and carries a maximum CVSS severity score of 10.0.

CVE-2026-85706 is a path traversal vulnerability in GitLab’s repository commits API. GitLab said that, under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication enforcement to read arbitrary files from an affected GitLab server.

Path traversal flaws occur when an application fails to properly restrict file paths supplied through requests. In this case, exploitation could allow an external attacker to move outside the intended repository directory structure and request files elsewhere on the server.

The exposure is particularly serious because it requires no account, user interaction, or prior access, substantially lowering the barrier to internet-based exploitation.

The vulnerability affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. Organizations operating self-managed GitLab instances should identify exposed assets immediately and upgrade to GitLab 19.1.8, 19.2.6, 19.3.2, or a later supported release, depending on their deployment branch.

CISA added the flaw to the KEV catalog on September 11, 2026, and set a remediation deadline of September 14, 2026, for federal civilian executive branch agencies.

The agency has also marked the issue as requiring forensic triage under Binding Operational Directive 26-04, reflecting the possibility that vulnerable systems may already have been accessed before patching.

Although CISA currently lists ransomware use as unknown, GitLab servers are high-value targets because they can host proprietary source code, CI/CD configurations, access tokens, deployment scripts, and other sensitive development data.

Arbitrary file disclosure can also help attackers identify credentials, secrets, configuration details, and other information useful for follow-on intrusion activity.

Security teams should prioritize patching internet-facing GitLab systems, review GitLab and reverse-proxy logs for unusual repository commits API requests, and investigate unexpected file-access patterns. Teams should also rotate potentially exposed credentials, tokens, and secrets after assessing the scope of any compromise.

GitLab credited security researcher s3ntago for reporting the flaw through its HackerOne bug bounty program. The weakness is associated with CWE-35, a category covering improper limitation of pathname access that can enable attackers to access files outside an intended restricted directory.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago