GitLab Path Traversal Allows Unauthenticated File Read
GitLab CE/EE contains a path traversal flaw due to improper path confinement and missing access controls, allowing an unauthenticated attacker to read arbitrary files from the server.
- Vendor
- GitLab
- Product
- GitLab CE/EE
- CVSS
- 10.0
- EPSS (exploit probability)
- N/A
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
CVE-2026-85706 is a path traversal vulnerability in GitLab Community Edition and Enterprise Edition. The flaw stems from improper path confinement and missing access controls, allowing an unauthenticated remote attacker to read arbitrary files from the GitLab server filesystem.
GitLab disclosed and patched this vulnerability on September 11, 2026, in patch release 19.3.2. In-the-wild exploitation probes began within hours of disclosure. CISA added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog on September 11, 2026.
Affected versions: GitLab CE/EE prior to 19.3.2. Check the GitLab patch release notes for the full version matrix.
Fix: Upgrade to GitLab 19.3.2 or later.
