A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove
Summary
A critical path traversal vulnerability, CVE-2026-85706, has been discovered in GitLab's repository commits API, allowing attackers to read arbitrary files on vulnerable servers. This flaw, rated with a maximum severity score, could expose sensitive data like credentials and secrets. GitLab has released a patch and advises immediate application for self-hosted instances.
IFF Assessment
This vulnerability allows attackers to read sensitive files, posing a direct threat to the security of organizations using GitLab.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 14, 2026. Known ransomware use: Unknown.
Defender Context
This critical vulnerability highlights the importance of promptly patching development infrastructure like GitLab, which often contains sensitive secrets and credentials. Defenders should prioritize updating affected systems and consider network segmentation to limit the blast radius of any potential exploit. The frequent discovery of such high-severity flaws underscores the need for continuous security monitoring and rapid incident response in DevOps environments.