Vulnerability threat dossier

CVE-2026-85706

gitlabgitlab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

VTP deterministic threat48.9of 100 · CVSS excluded

VTP analyst assessment

GitLab unauthenticated arbitrary file read

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence90%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this GitLab path traversal flaw as exploited. An unauthenticated user can read arbitrary server files through the repository commits API when affected versions meet the stated conditions. Public Nuclei coverage lowers the effort needed to identify vulnerable instances.

Why it matters

  • GitLab servers can contain source code, configuration, and credentials.
  • GitLab remediated affected releases through 19.3 before 19.3.2.

Evidence

4 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The public reports do not identify affected customer instances or specific stolen files.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use self-managed GitLab, update to the remediated release for your version branch.

AI baseline history (14)
  1. BASELINE ASSESSED
    GitLab unauthenticated arbitrary file readgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Actively exploited GitLab repository API arbitrary file readgpt-5.6-terra · low
  3. BASELINE ASSESSED
    GitLab CE/EE unauthenticated arbitrary file readgpt-5.6-terra · low
  4. BASELINE ASSESSED
    GitLab path traversal is known exploitedgpt-5.6-terra · low
  5. BASELINE ASSESSED
    GitLab repository commits API path traversalgpt-5.6-terra · low
  6. BASELINE ASSESSED
    GitLab path traversal is actively exploitedgpt-5.6-terra · low
  7. BASELINE ASSESSED
    GitLab path traversal under active exploitationgpt-5.6-terra · low
  8. BASELINE ASSESSED
    GitLab path traversal flaw has reported exploitation and public template coveragegpt-5.6-terra · low
  9. BASELINE ASSESSED
    GitLab unauthenticated path traversal and file readgpt-5.6-terra · low
  10. BASELINE ASSESSED
    GitLab unauthenticated arbitrary-file read is exploitedgpt-5.6-terra · low
  11. BASELINE ASSESSED
    GitLab unauthenticated arbitrary file-read flawgpt-5.6-terra · low
  12. BASELINE ASSESSED
    GitLab path traversalgpt-5.6-terra · low
  13. BASELINE ASSESSED
    Unresolved GitLab CVE mappinggpt-5.6-terra · low
  14. BASELINE ASSESSED
    Reported GitLab path traversal with incomplete metadatagpt-5.6-terra · low

Previous AI priority: CRITICAL → current: CRITICAL. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.0995th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.09; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

ACTIVE EXPLOITATIONActive Exploitation
RESEARCH PUBLICATIONNew technical research
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
CERT ADVISORYNew CERT advisory
03

Claim provenance

Evidence and source independence

10publications detected
10underlying evidence chains

2 primary sources · 0 dependent secondary reports · 7 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
82%claim confidence
INDEPENDENTreport:f5c7c9802b4070a57ace8e3cd51ad70846eadbf6ab3b7b093ab6b5fc8e1a47a5ACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:c405b1afbb5254c02eb8f8b08e6b00b29c9864c9fd1dd8f216b3f21a43841ee2ACTIVE
Evidence
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:0cb51d4bfae945e5ec2644fc8c2d2e6ea84bbffeACTIVE
Evidence
04

Event history

Threat timeline

  1. 14:5916 Sept
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-85706.

  2. 10:0214 Sept
    ACTIVE EXPLOITATION

    Active Exploitation

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 10:0214 Sept
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-85706.

  4. 07:0614 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  5. 17:1013 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  6. 00:0011 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  7. 00:0011 Sept
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-85706.

05

Original publications

Source record

Nuclei Templates v10.4.9 - Release Notes

New Templates Added: 123 | CVEs Added: 85 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-86207 ] N-able N-central - Authentication Bypass ( @rapid7 , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-85706 ] GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read ( @flx ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-83548 ] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB ( @rapid7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82329 ] JFrog Artifactory Access Blank Join Key Authentication Bypass ( @johnk3r , @pruva ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82222 ] GiveWP <= 4.16.7.1 - Remote Code Execution (@0x_Akoko, @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-81578 ] PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct ( @darses , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-73570 ] Zimbra Collaboration Suite < 10.1.20 - OS Command Injection (@0x_Akoko, @ritikchaddha ) [high] (kev) (vKEV) 🔥 [ CVE-2026-55040 ] Microsoft SharePoint Server - JWT Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48558 ] SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-41948 ] Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-32475 ] Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler ( @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-18963 ] Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-18577 ] N-able N-central < 2026.3.1.10 - Authentication Bypass ( @patrick-threatmate ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9586 ] Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1281 ] Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection ( @rxerium ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-0768 ] Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2024-1708 ] ConnectWise ScreenConnect <= 23.9.7 - Path Traversal ( @Popy21 ) [high] (kev) (vKEV) 🔥 [ CVE-2023-54391 ] Proxmox VE - Default Credentials with TFA Bypass ( @dhiyaneshdk , @0x_Akoko) [critical] (vKEV) 🔥 [ CVE-2020-10221 ] rConfig <= 3.9.4 - Authenticated OS Command Injection ( @Jayachandran from Securin Labs ( https://securin.io )) [high] (kev) (vKEV) 🔥 [ CVE-2019-11043 ] PHP-FPM Path Info Buffer Underflow - Remote Code Execution ( @prasath from Securin Labs ( https://securin.io )) [critical] (kev) (vKEV) 🔥 [ CVE-2017-7504 ] JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization ( @Jayachandran ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed the CVE-2026-41042 template filename so the template loads correctly (PR #17024 , Issue #17022 ). Corrected the filename casing on CVE-2025-14047 .yaml (PR #16994 ). Resolved an unresolved nested payload variable in CVE-2026-4257 that stopped the WordPress Contact Form by Supsystic template running on nuclei v3.11.1 (PR #17039 ). Fixed the matched_feature extractor in CVE-2026-76904 .yaml (PR #16969 ). Corrected the author field in CVE-2026-61511 .yaml (PR #16976 ). Removed six imprecise CVE templates whose proofs of concept were not reliable — CVE-2016-3714 , CVE-2018-10933 , CVE-2018-15708 , CVE-2019-8942 , CVE-2019-17554 and CVE-2020-2555 (PR #16567 ). False Negatives CVE-2021-43798 — the Grafana arbitrary file read template now fires on instances sitting behind an nginx reverse proxy (PR #17185 ). CVE-2018-3760 — restored broken detection on Ruby on Rails local file inclusion using disable-path-automerge and a flow block (PR #17235 ). CVE-2021-34429 — replaced unsafe with disable-path-automerge so the Jetty request path is no longer duplicated (PR #17236 ). CVE-2024-52433 — the My Geo Posts Free template could never match a genuin

CVE-2016-3714CVE-2017-7504CVE-2017-8225CVE-2018-10933CVE-2018-15708CVE-2018-3760CVE-2019-11043CVE-2019-17554CVE-2019-8942CVE-2020-10221CVE-2020-2555CVE-2020-29134CVE-2021-34429CVE-2021-43798CVE-2022-39258CVE-2023-54391CVE-2024-1708CVE-2024-52433CVE-2025-14047CVE-2025-14998CVE-2025-15403CVE-2025-29927CVE-2025-51683CVE-2025-53887CVE-2025-57231CVE-2026-0561CVE-2026-0650CVE-2026-0702CVE-2026-0743CVE-2026-0768CVE-2026-11801CVE-2026-1281CVE-2026-12898CVE-2026-18577CVE-2026-18963CVE-2026-19092CVE-2026-19632CVE-2026-2113CVE-2026-21875CVE-2026-23491CVE-2026-23536CVE-2026-23693CVE-2026-26265CVE-2026-27454CVE-2026-27960CVE-2026-28141CVE-2026-28411CVE-2026-29962CVE-2026-29963CVE-2026-30849CVE-2026-32475CVE-2026-33017CVE-2026-34234CVE-2026-41042CVE-2026-41452CVE-2026-41456CVE-2026-41679CVE-2026-41948CVE-2026-42221CVE-2026-4257CVE-2026-42596CVE-2026-42878CVE-2026-44177CVE-2026-44343CVE-2026-48558CVE-2026-53595CVE-2026-55040CVE-2026-55229CVE-2026-5524CVE-2026-5562CVE-2026-56292CVE-2026-57582CVE-2026-58123CVE-2026-58191CVE-2026-59177CVE-2026-59509CVE-2026-59726CVE-2026-60105CVE-2026-61511CVE-2026-61736CVE-2026-62382CVE-2026-65761CVE-2026-72898CVE-2026-73034CVE-2026-73570CVE-2026-7467CVE-2026-76904CVE-2026-77806CVE-2026-81199CVE-2026-81578CVE-2026-82222CVE-2026-82329CVE-2026-83548CVE-2026-8467CVE-2026-85200CVE-2026-85706CVE-2026-86206CVE-2026-86207CVE-2026-86426CVE-2026-87820CVE-2026-88062CVE-2026-9133CVE-2026-9586
Separate evidence group
Original

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

CVE-2026-85706
Separate evidence group
Original

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

CVE-2021-24084CVE-2021-38003CVE-2021-41379CVE-2025-20701CVE-2025-53521CVE-2026-10090CVE-2026-12645CVE-2026-12646CVE-2026-12647CVE-2026-12650CVE-2026-12744CVE-2026-12745CVE-2026-18667CVE-2026-20293CVE-2026-26084CVE-2026-33197CVE-2026-42016CVE-2026-42018CVE-2026-44756CVE-2026-50656CVE-2026-51990CVE-2026-58240CVE-2026-61578CVE-2026-61582CVE-2026-61583CVE-2026-61584CVE-2026-61585CVE-2026-61587CVE-2026-61600CVE-2026-61601CVE-2026-61602CVE-2026-6485CVE-2026-67401CVE-2026-69414CVE-2026-70647CVE-2026-70648CVE-2026-76578CVE-2026-78546CVE-2026-78547CVE-2026-81578CVE-2026-81963CVE-2026-82078CVE-2026-82329CVE-2026-82533CVE-2026-84282CVE-2026-84286CVE-2026-84388CVE-2026-84390CVE-2026-84393CVE-2026-85046CVE-2026-85102CVE-2026-85103CVE-2026-85706CVE-2026-85880CVE-2026-87491
Separate evidence group
Original

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score of 10.0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04. Organizations running affected self-managed GitLab instances should remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles. Mitigation guidance A vendor-supplied update is available to remediate CVE-2026-85706. Organizations running affected self-managed GitLab CE or EE instances should upgrade to a fixed version immediately. Affected GitLab CE/EE versions Fixed version All versions from 18.7 before 19.1.8 19.1.8 All versions from 19.2 before 19.2.6 19.2.6 All versions from 19.3 before 19.3.2 19.3.2 GitLab.com is already running a patched version, and GitLab Dedicated customers do not need to take action. Per GitLab, all self-managed deployment types are affected, including Omnibus, source code, and Helm chart deployments. The updates include database migrations. Single-node installations will experience downtime while the migrations run; multi-node deployments can use GitLab's zero-downtime upgrade procedure. Of the fixed releases, only 19.3.2 includes post-deployment migrations. The patch release also addresses 17 other vulnerabilities. These include CVE-2026-87719 , a critical insecure deserialization vulnerability ( CWE-502 ) in GitLab EE with a CVSSv3.1 score of 9.9 . GitLab states that, under certain conditions, an authenticated user with Duo Chat access could obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument. At the time of publication, only CVE-2026-85706 is known to be exploited in the wild. Given the confirmed exploitation, Rapid7 strongly recommends looking for signs of compromise even after the update has been applied. Organizations subject to CISA's BOD 26-04 should also follow the forensic triage requirements associated with the KEV entry. For the latest mitigation guidance, please refer to the vendor's security advisory . Rapid7 customers Exposure Command, InsightVM, and Nexpose Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-85706 with a vulnerability check available in the September 15 content release. Updates September 14, 2026 : Initial publication.

CVE-2026-85706CVE-2026-87719
Separate evidence group
Original

CISA: Hackers now exploit max severity GitLab flaw in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]

CVE-2021-22175CVE-2021-39935CVE-2026-85706
Separate evidence group
Original

Exploit tooling coverage changed for 1 CVE

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 1 CVE in this pinned revision. 1 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2026-85706
Separate evidence group
Original

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

CVE-2026-19478CVE-2026-85706CVE-2026-87719
Separate evidence group
Original

GitLab Vulnerability Exploited One Day After Disclosure

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek .

CVE-2026-85706CVE-2026-87719
Separate evidence group
Original

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]

CVE-2021-22175CVE-2021-39935CVE-2023-2825CVE-2026-85706CVE-2026-87719
Separate evidence group
Original

Multiples vulnérabilités dans GitLab (11 septembre 2026)

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

CVE-2024-11222CVE-2025-14871CVE-2026-1168CVE-2026-12910CVE-2026-13210CVE-2026-16794CVE-2026-19619CVE-2026-3855CVE-2026-7514CVE-2026-78252CVE-2026-79708CVE-2026-8030CVE-2026-82837CVE-2026-85706CVE-2026-86340CVE-2026-86341CVE-2026-87719CVE-2026-88765
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score48.9vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction1.86 / 20
Exploit availability7.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE
CWE-22
CPE records
2
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.