GitLab Critical Vulnerability (CVE-2026-85706) Actively Exploited, Allowing Arbitrary File Reads
A critical path traversal vulnerability (CVE-2026-85706) in GitLab, with a CVSS score of 10.0, is being actively exploited in the wild. The flaw allows an unauthenticated attacker to read arbitrary files from a GitLab server by sending a single HTTP POST request to the /api/v4/projects/{id}/repository/commits/ endpoint, provided the instance hosts at least one public project. GitLab released patches on September 10, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog, mandating remediation by September 14.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai