VMTech
Discuss a project

GitLab releases fixes for CVSS 10 repository API file-read flaw

GitLab releases fixes for CVSS 10 repository API file-read flaw

GitLab patches maximum-severity repository API flaw

GitLab has released security updates for Community Edition and Enterprise Edition to fix CVE-2026-85706, a path traversal vulnerability rated CVSS 10.0. watchTowr said it observed probes targeting the issue in the wild from 06:00 UTC on September 11, 2026, only hours after public disclosure.

The flaw affects GitLab CE and EE versions from 18.7 before 19.1.8, versions from 19.2 before 19.2.6, and versions from 19.3 before 19.3.2. GitLab has issued fixed releases 19.1.8, 19.2.6 and 19.3.2.

CVE-2026-85706 is located in the repository commits API. GitLab attributed the defect to improper path confinement and missing authentication enforcement. Under certain conditions, an unauthenticated user could read arbitrary files from the GitLab server.

Why exposed self-managed deployments need attention

watchTowr said an external attacker could use the weakness to read log files and GitLab-specific configuration files, potentially obtaining credentials, secrets and other sensitive information. Exploitation requires at least one public project to exist, the firm said.

The potential impact extends beyond a single file disclosure. Jake Knott, head of threat intelligence at watchTowr, said unauthorised access to GitLab can expose source code, CI/CD secrets and credentials, and may enable code injection into build pipelines. That can create risks for systems and artefacts downstream of those pipelines.

Knott noted that this is the second critical GitLab issue in recent weeks, following the GraphQL code injection vulnerability CVE-2026-19478, which was almost immediately actively exploited. He warned that the current flaw could move to indiscriminate mass exploitation quickly.

A second critical fix affects GitLab EE

The same GitLab releases also address CVE-2026-87719, an insecure deserialization vulnerability in GitLab EE with a CVSS score of 9.9. GitLab said an authenticated user with Duo Chat access could use a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.

That issue could expose Advanced Search instance configurations and sensitive credentials. Its access requirement differs from CVE-2026-85706, but both fixes are included in the same 19.1.8, 19.2.6 and 19.3.2 updates.

Immediate operational steps

Organisations operating self-managed GitLab instances exposed to the internet should apply the available patches as soon as possible. Where an update cannot be applied immediately, GitLab recommends limiting public access when it is not required.

Teams should also review logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.Path parameters, as watchTowr identified those as potential indicators of exploitation attempts. The practical priority is to patch affected instances, reduce unnecessary public exposure and investigate relevant request activity.

#gitlab#cybersecurity#vulnerability#devsecops
Open analytics
On the site 1 views
min read 3 11.09.2026
Instagram

GitLab releases fixes for CVSS 10 repository API file-read flaw

Open the post on Instagram ↗