CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
Published Sep 11, 2026
·Updated
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
Affected Software
1 affected component
GitLab Community Edition and Enterprise Edition
Event History
Sep 11, 2026
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Frequently Asked Questions
1
Is exploitation in the wild known?
Yes. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-11.
2
Does an attacker need an account to exploit this issue?
No. The issue is described as exploitable by an unauthenticated user.
3
Is vendor patch information available?
Yes. A GitLab patch-release reference is provided for GitLab 19.3.2, but the supplied data does not identify the full affected or fixed version ranges.