Maximum Severity GitLab Flaw Puts Supply Chains at Risk

Summary

A critical path traversal vulnerability, designated CVE-2026-85706, has been discovered in GitLab Community Edition and Enterprise Edition. This flaw carries a maximum CVSS score of 10.0, indicating a severe risk to users.

IFF Assessment

FOE

A critical vulnerability with a high CVSS score in a widely used development platform poses a significant threat to software supply chains and organizations relying on GitLab.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating this vulnerability in their GitLab instances immediately. The severity of this flaw means attackers could potentially gain significant access, compromising code repositories and downstream projects, thus impacting the entire software supply chain.

Read Full Story →