Critical Path Traversal Vulnerability (CVE-2026-85706) Discovered in GitLab

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-12
Category: technology
Source: CVE Record

GitLab has remediated a critical path traversal vulnerability (CVE-2026-85706) in GitLab CE/EE, affecting versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. This flaw could allow an unauthenticated user to read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai