GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Summary

GitLab has released patches for several security vulnerabilities, including a critical CVE-2026-85706 (CVSS 10.0) path traversal flaw. This vulnerability allows unauthenticated users to read arbitrary files from the GitLab server and has already seen in-the-wild probes shortly after its disclosure.

IFF Assessment

FOE

The discovery and exploitation of a critical remote code execution vulnerability in GitLab poses a significant threat to organizations using the platform, making it bad news for defenders.

Severity

10.0 Critical

The CVSS score of 10.0 reflects the severity of a path traversal vulnerability that allows unauthenticated remote code execution, enabling an attacker to read arbitrary files from the server.

Defender Context

This critical vulnerability in GitLab requires immediate attention from defenders. Organizations should prioritize patching to mitigate the risk of unauthorized file access and potential further compromise. Monitoring for exploitation attempts related to this CVE is also crucial.

Read Full Story →