Cyber Security News

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution.

The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September 10, 2026.

GitLab has urged administrators of self-managed instances to upgrade immediately. The patched release is already in effect for GitLab.com, while GitLab Dedicated customers do not need to take any action.

Critical GitLab Flaws

The most severe issue, tracked as CVE-2026-85706, is a CVSS score of 10.0 path-traversal vulnerability found in the repository commits API.

Under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication enforcement to read arbitrary files from the GitLab server.

This poses a significant risk, particularly for GitLab servers exposed to the internet, because it requires no account or user interaction. Such arbitrary-file read vulnerabilities could potentially expose application configuration, secrets, tokens, private keys, and other sensitive server-side information, depending on file permissions and deployment configuration.

The second critical flaw, CVE-2026-87719, affects GitLab Enterprise Edition instances with Duo Chat access. An authenticated attacker could submit a specially crafted GraphQL subscription argument that bypasses serialization controls, allowing access to server-object lookups and the retrieval of Advanced Search instance configuration data and sensitive credentials. GitLab has assigned this issue a CVSS score of 9.9.

GitLab has also patched CVE-2026-88765, a high-severity buffer overflow vulnerability in the Unicode conversion wrapper used during Advanced Search indexing.

An authenticated GitLab EE user could import a maliciously crafted Git project export, triggering the overflow and potentially achieving remote code execution.

Although this flaw requires authentication and has a high attack complexity, successful exploitation could give an attacker code execution capabilities on a GitLab server.

This outcome is particularly serious for DevOps infrastructure that stores source code, CI/CD secrets, package artifacts, and deployment workflows.

Additional fixes address the exposure of protected CI/CD variables, authorization weaknesses, stored or reflected cross-site scripting vulnerabilities, SAML SSO restriction bypasses, package-registry tampering, and GraphQL denial-of-service attacks.

Affected Versions and Fixes

The critical arbitrary-file read vulnerability affects GitLab CE/EE versions from 18.7 up to the newly released fixed versions. The GraphQL credential-exposure flaw impacts GitLab EE from version 18.3. At the same time, the project-import remote code execution issue affects GitLab EE versions dating back to 12.3.

Administrators should upgrade to the applicable patched version:

  • GitLab 19.3 → 19.3.2
  • GitLab 19.2 → 19.2.6
  • GitLab 19.1 → 19.1.8

Organizations using older affected branches should transition to a supported, patched release as soon as operationally feasible. Security teams should also review GitLab application logs, API activity, project-import events, GraphQL subscription requests, and access to CI/CD variables for suspicious behavior.

CVE Details

CVESeverity / CVSSAffected EditionVulnerability and Security Impact
CVE-2026-85706Critical / 10.0CE/EEUnauthenticated path traversal in repository commits API enables arbitrary-file reads
CVE-2026-87719Critical / 9.9EEInsecure GraphQL subscription deserialization may expose Advanced Search configurations and credentials
CVE-2026-88765High / 8.5EECrafted project export can trigger a Unicode conversion buffer overflow and potential RCE
CVE-2026-79708High / 8.5EEDevelopers may run policy test pipelines and access protected CI/CD variables
CVE-2026-78252High / 8.2CE/EEMarkdown JSON table rendering weakness can induce unintended state-changing requests
CVE-2026-13210High / 7.7CE/EECI/CD environment scope matcher may expose variables outside their intended scope
CVE-2025-14871High / 7.5CE/EEUnauthenticated GraphQL complexity calculation can cause denial of service
CVE-2026-1168High / 7.5CE/EEUnauthenticated GraphQL complexity limiter flaw can cause denial of service
CVE-2024-11222Medium / 6.4CE/EEMerge-request pipeline race condition may permit actions in another user’s commit context
CVE-2026-12910Medium / 5.4CE/EEAuthenticated users may bypass SAML SSO sign-in restrictions
CVE-2026-82837Medium / 5.3CE/EEWorkhorse senddata emitters may expose sensitive credentials or tokens
CVE-2026-19619Medium / 4.7CE/EEContent Editor HTML sanitization issue enables JavaScript execution in a target session
CVE-2026-86341Medium / 4.4EEOwners or Maintainers could disable protected-environment approval requirements
CVE-2026-86340Medium / 4.4EEDeleting the sole approver can bypass protected-environment deployment approvals
CVE-2026-7514Medium / 4.3CE/EEDevelopers may replace Generic Package Registry content and hide packages
CVE-2026-8030Medium / 4.3CE/EENamespace-transfer validation flaw can prevent group-setting modifications
CVE-2026-16794Medium / 4.3EESecurity Managers may execute CI/CD jobs and access protected group-project variables
CVE-2026-3855Low / 3.1CE/EETerraform State API flaw may disclose restricted files or cause denial of service

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

3 hours ago

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…

3 hours ago

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…

3 hours ago

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…

4 hours ago

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…

4 hours ago

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to…

5 hours ago