The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks.
The issue affects both GitLab Community Edition and Enterprise Edition and requires urgent mitigation, particularly for internet-accessible GitLab instances.
CVE-2026-85706 is a path traversal vulnerability in GitLab’s repository commits API. An unauthenticated attacker can exploit improper path confinement and missing authentication enforcement to read arbitrary files from a vulnerable GitLab server.
This weakness is associated with CWE-35, which covers improper path limitation that can allow an attacker to access files outside an intended directory.
Arbitrary file disclosure can be severe in a source-code management environment. Depending on GitLab’s deployment configuration and the affected service’s permissions, exposed files could include application configuration data, secrets, access tokens, private keys, environment variables, repository metadata, or other sensitive artifacts.
Attackers may use those materials to map internal infrastructure, access source code, steal credentials, or establish a path toward further compromise.
CISA added the vulnerability to its catalog on September 11, 2026, and set a remediation due date of September 14, 2026.
The agency instructed affected organizations to apply mitigations according to vendor guidance while complying with Binding Operational Directive 26-04, which prioritizes security updates based on risk. The advisory also marks the flaw as requiring forensic triage under BOD 26-04.
The short remediation window reflects the risk associated with a remotely exploitable, unauthenticated flaw in a platform frequently connected to software development, CI/CD workflows, package registries, deployment automation, and enterprise identity systems.
A compromised GitLab instance can give attackers a valuable foothold in the software supply chain, especially when stored project variables or automation credentials provide access to cloud accounts and production environments.
Organizations should identify every GitLab CE and EE deployment, including self-hosted instances, cloud-connected installations, development environments, and externally managed systems.
Security teams should prioritize assets exposed to the public internet and verify whether any instances are behind reverse proxies, web application firewalls, or single sign-on systems that may create a false assumption that the vulnerable API cannot be reached.
CISA said organizations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of affected products if adequate mitigations are unavailable.
The agency also said stakeholders must evaluate each asset’s internet exposure and ensure adherence to federal patching requirements.
Because forensic triage is required, defenders should review GitLab and web-server logs for unusual unauthenticated requests to repository commits API endpoints, unexpected file-path parameters, traversal sequences, anomalous response sizes, and signs of follow-on credential use.
Teams should also rotate potentially exposed credentials, including personal access tokens, deploy tokens, CI/CD variables, SSH keys, and cloud access secrets, after remediation.
CISA has not indicated whether CVE-2026-85706 is being used in ransomware campaigns. The absence of confirmed ransomware use should not reduce urgency, since arbitrary file-read vulnerabilities can enable reconnaissance and credential theft that later support broader intrusion activity.
Detect 58% more threats with fresh intelligence from 16K+ organizations. Integrate TI Feeds in you SOC
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and…
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel…
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious…
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than…
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…