< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-11T22:00:18+05:30

Critical GitLab Path Traversal Vulnerability (CVE-2026-85706) Exploited in Real-World Attacks

A critical path traversal vulnerability (CVE-2026-85706) in GitLab allows unauthenticated file reads with a CVSS score of 10.0, already targeted in real-world attacks. Patches are urgently recommended for affected versions to prevent exploitation of sensitive data and CI/CD pipelines.

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.

The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

Read original article

*** END OF TRANSMISSION ***