Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-85706

CRITICAL Actively Exploited NVDCISA KEV
CVSS Score 10
Severity CRITICAL
Published Sep 12, 2026
Vendor unknown
This vulnerability is in the CISA Known Exploited Vulnerabilities Catalog. Active exploitation has been observed. Immediate patching is recommended.

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

References