CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Summary
A path traversal vulnerability in GitLab Community Edition and Enterprise Edition allows unauthenticated users to read arbitrary files. This is due to improper path confinement and missing authentication enforcement in the repository commits API.
IFF Assessment
The identified vulnerability allows unauthenticated users to access sensitive files, posing a direct threat to data confidentiality and integrity.
Severity
The vulnerability has a high attack complexity and impact, allowing unauthenticated remote access to read arbitrary files, leading to information disclosure.
CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in GitLab allows attackers to read arbitrary files without authentication, which could expose sensitive configuration or data. Defenders should prioritize applying vendor-provided mitigations and adhering to CISA's guidance on prioritizing security updates.