GitLab Patched Critical File Access Vulnerability

A path-traversal flaw allowed unauthenticated attackers to read arbitrary files from affected server instances.

Updated on Oct. 3, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stylized industrial server cabinet, representing critical security infrastructure.
GitLab has issued critical security patches for CVE-2026-85706, a path-traversal vulnerability that allowed unauthenticated attackers to access arbitrary server files. AI Illustration. Upload story photo >

Live Poll

Do you trust that major software platforms sufficiently protect your data from unauthenticated access?

On September 11, 2026, GitLab released security patches for CVE-2026-85706, a critical path-traversal vulnerability that enabled unauthenticated remote attackers to read arbitrary files from server instances. This flaw affected versions 18.7 through 19.3.1 and was actively exploited in the wild.

Why it matters

The vulnerability poses a severe risk to data integrity and confidentiality because it allows for unauthenticated remote file exfiltration. Its presence in the CISA Known Exploited Vulnerabilities Catalog underscores the necessity for immediate patching in environments containing at least one public project.

The vulnerability carries a CVSS score of 10.0, the highest possible severity rating, indicating critical risk for any exposed system. It affected GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1.

The players

GitLab

A devops platform providing software development, CI/CD, and security tools that serves as a central repository for source code.

CISA

The Cybersecurity and Infrastructure Security Agency is the United States federal body responsible for maintaining the Known Exploited Vulnerabilities Catalog.

Mohamed Abdelaiz

The security researcher who identified and reported the vulnerability.

The details

Attackers exploited this flaw through the repository commits API, leveraging improper path confinement and a total failure of authentication enforcement to read arbitrary files. A path-traversal vulnerability — a security weakness that allows an attacker to access files and directories stored outside the web root folder — requires the targeted GitLab instance to host at least one public project. Administrators can detect exploitation attempts by inspecting log files for anomalous HTTP POST requests.

Timeline

  1. September 11, 2026: GitLab released security patches to address the vulnerability.

The Tech Race

The inclusion of this flaw in the CISA Known Exploited Vulnerabilities Catalog highlights the systemic risk associated with repository-level access control failures. It marks a significant security event in the ongoing race to harden CI/CD pipelines against remote, unauthenticated file access.

Administrators must audit their instances and ensure they are patched to versions 19.0.9, 18.11.12, or newer versions within the 19.1, 19.2, and 19.3 series. Those unable to update immediately should inspect logs for unauthorized HTTP POST requests to the repository commits API to identify potential prior breaches.

The takeaway

Critical path-traversal flaws in central devops infrastructure demonstrate why repository access controls are a primary target for remote attackers. Organizations should confirm their GitLab build version and monitor for anomalous API traffic to identify potential unauthorized file access.

Further reading

Review current security practices and mitigation strategies for development environments in our Cybersecurity section.

Source note: This article includes information reported by InfoQ.

Live Poll

Do you trust that major software platforms sufficiently protect your data from unauthenticated access?