Thursday, October 1, 2026

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution.

The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September 10, 2026.

GitLab has urged administrators of self-managed instances to upgrade immediately. The patched release is already in effect for GitLab.com, while GitLab Dedicated customers do not need to take any action.

Critical GitLab Flaws

The most severe issue, tracked as CVE-2026-85706, is a CVSS score of 10.0 path-traversal vulnerability found in the repository commits API.

Under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication enforcement to read arbitrary files from the GitLab server.

This poses a significant risk, particularly for GitLab servers exposed to the internet, because it requires no account or user interaction. Such arbitrary-file read vulnerabilities could potentially expose application configuration, secrets, tokens, private keys, and other sensitive server-side information, depending on file permissions and deployment configuration.

The second critical flaw, CVE-2026-87719, affects GitLab Enterprise Edition instances with Duo Chat access. An authenticated attacker could submit a specially crafted GraphQL subscription argument that bypasses serialization controls, allowing access to server-object lookups and the retrieval of Advanced Search instance configuration data and sensitive credentials. GitLab has assigned this issue a CVSS score of 9.9.

GitLab has also patched CVE-2026-88765, a high-severity buffer overflow vulnerability in the Unicode conversion wrapper used during Advanced Search indexing.

An authenticated GitLab EE user could import a maliciously crafted Git project export, triggering the overflow and potentially achieving remote code execution.

Although this flaw requires authentication and has a high attack complexity, successful exploitation could give an attacker code execution capabilities on a GitLab server.

This outcome is particularly serious for DevOps infrastructure that stores source code, CI/CD secrets, package artifacts, and deployment workflows.

Additional fixes address the exposure of protected CI/CD variables, authorization weaknesses, stored or reflected cross-site scripting vulnerabilities, SAML SSO restriction bypasses, package-registry tampering, and GraphQL denial-of-service attacks.

Affected Versions and Fixes

The critical arbitrary-file read vulnerability affects GitLab CE/EE versions from 18.7 up to the newly released fixed versions. The GraphQL credential-exposure flaw impacts GitLab EE from version 18.3. At the same time, the project-import remote code execution issue affects GitLab EE versions dating back to 12.3.

Administrators should upgrade to the applicable patched version:

  • GitLab 19.3 → 19.3.2
  • GitLab 19.2 → 19.2.6
  • GitLab 19.1 → 19.1.8

Organizations using older affected branches should transition to a supported, patched release as soon as operationally feasible. Security teams should also review GitLab application logs, API activity, project-import events, GraphQL subscription requests, and access to CI/CD variables for suspicious behavior.

CVE Details

CVESeverity / CVSSAffected EditionVulnerability and Security Impact
CVE-2026-85706Critical / 10.0CE/EEUnauthenticated path traversal in repository commits API enables arbitrary-file reads
CVE-2026-87719Critical / 9.9EEInsecure GraphQL subscription deserialization may expose Advanced Search configurations and credentials
CVE-2026-88765High / 8.5EECrafted project export can trigger a Unicode conversion buffer overflow and potential RCE
CVE-2026-79708High / 8.5EEDevelopers may run policy test pipelines and access protected CI/CD variables
CVE-2026-78252High / 8.2CE/EEMarkdown JSON table rendering weakness can induce unintended state-changing requests
CVE-2026-13210High / 7.7CE/EECI/CD environment scope matcher may expose variables outside their intended scope
CVE-2025-14871High / 7.5CE/EEUnauthenticated GraphQL complexity calculation can cause denial of service
CVE-2026-1168High / 7.5CE/EEUnauthenticated GraphQL complexity limiter flaw can cause denial of service
CVE-2024-11222Medium / 6.4CE/EEMerge-request pipeline race condition may permit actions in another user’s commit context
CVE-2026-12910Medium / 5.4CE/EEAuthenticated users may bypass SAML SSO sign-in restrictions
CVE-2026-82837Medium / 5.3CE/EEWorkhorse senddata emitters may expose sensitive credentials or tokens
CVE-2026-19619Medium / 4.7CE/EEContent Editor HTML sanitization issue enables JavaScript execution in a target session
CVE-2026-86341Medium / 4.4EEOwners or Maintainers could disable protected-environment approval requirements
CVE-2026-86340Medium / 4.4EEDeleting the sole approver can bypass protected-environment deployment approvals
CVE-2026-7514Medium / 4.3CE/EEDevelopers may replace Generic Package Registry content and hide packages
CVE-2026-8030Medium / 4.3CE/EENamespace-transfer validation flaw can prevent group-setting modifications
CVE-2026-16794Medium / 4.3EESecurity Managers may execute CI/CD jobs and access protected group-project variables
CVE-2026-3855Low / 3.1CE/EETerraform State API flaw may disclose restricted files or cause denial of service

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection. 

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Next.js ImageResponse Vulnerability Lets Remote Attackers Execute Code Through SVG Content

A critical vulnerability in Next.js could let unauthenticated remote...

Axios Flaws Let Attackers Bypass Proxy Controls and Trigger SSRF Attacks

Axios maintainers have disclosed several high-severity security vulnerabilities that...

China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor

A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints...

Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation

TeamViewer has issued security bulletin TV-2026-1010 to address five...

CloudSyncD Uses Invisible Unicode to Hide Phished Mac Passwords in Plain Sight

A new macOS backdoor, tracked as CloudSyncD, that masquerades...

Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos

Security researchers have identified 543,699 unique credentials that remain...

Related Articles

Recent News