GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution.
The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September 10, 2026.
GitLab has urged administrators of self-managed instances to upgrade immediately. The patched release is already in effect for GitLab.com, while GitLab Dedicated customers do not need to take any action.
The most severe issue, tracked as CVE-2026-85706, is a CVSS score of 10.0 path-traversal vulnerability found in the repository commits API.
Under certain conditions, an unauthenticated attacker could exploit improper path confinement and missing authentication enforcement to read arbitrary files from the GitLab server.
This poses a significant risk, particularly for GitLab servers exposed to the internet, because it requires no account or user interaction. Such arbitrary-file read vulnerabilities could potentially expose application configuration, secrets, tokens, private keys, and other sensitive server-side information, depending on file permissions and deployment configuration.
The second critical flaw, CVE-2026-87719, affects GitLab Enterprise Edition instances with Duo Chat access. An authenticated attacker could submit a specially crafted GraphQL subscription argument that bypasses serialization controls, allowing access to server-object lookups and the retrieval of Advanced Search instance configuration data and sensitive credentials. GitLab has assigned this issue a CVSS score of 9.9.
GitLab has also patched CVE-2026-88765, a high-severity buffer overflow vulnerability in the Unicode conversion wrapper used during Advanced Search indexing.
An authenticated GitLab EE user could import a maliciously crafted Git project export, triggering the overflow and potentially achieving remote code execution.
Although this flaw requires authentication and has a high attack complexity, successful exploitation could give an attacker code execution capabilities on a GitLab server.
This outcome is particularly serious for DevOps infrastructure that stores source code, CI/CD secrets, package artifacts, and deployment workflows.
Additional fixes address the exposure of protected CI/CD variables, authorization weaknesses, stored or reflected cross-site scripting vulnerabilities, SAML SSO restriction bypasses, package-registry tampering, and GraphQL denial-of-service attacks.
Affected Versions and Fixes
The critical arbitrary-file read vulnerability affects GitLab CE/EE versions from 18.7 up to the newly released fixed versions. The GraphQL credential-exposure flaw impacts GitLab EE from version 18.3. At the same time, the project-import remote code execution issue affects GitLab EE versions dating back to 12.3.
Administrators should upgrade to the applicable patched version:
Organizations using older affected branches should transition to a supported, patched release as soon as operationally feasible. Security teams should also review GitLab application logs, API activity, project-import events, GraphQL subscription requests, and access to CI/CD variables for suspicious behavior.
CVE Details
| CVE | Severity / CVSS | Affected Edition | Vulnerability and Security Impact |
|---|---|---|---|
| CVE-2026-85706 | Critical / 10.0 | CE/EE | Unauthenticated path traversal in repository commits API enables arbitrary-file reads |
| CVE-2026-87719 | Critical / 9.9 | EE | Insecure GraphQL subscription deserialization may expose Advanced Search configurations and credentials |
| CVE-2026-88765 | High / 8.5 | EE | Crafted project export can trigger a Unicode conversion buffer overflow and potential RCE |
| CVE-2026-79708 | High / 8.5 | EE | Developers may run policy test pipelines and access protected CI/CD variables |
| CVE-2026-78252 | High / 8.2 | CE/EE | Markdown JSON table rendering weakness can induce unintended state-changing requests |
| CVE-2026-13210 | High / 7.7 | CE/EE | CI/CD environment scope matcher may expose variables outside their intended scope |
| CVE-2025-14871 | High / 7.5 | CE/EE | Unauthenticated GraphQL complexity calculation can cause denial of service |
| CVE-2026-1168 | High / 7.5 | CE/EE | Unauthenticated GraphQL complexity limiter flaw can cause denial of service |
| CVE-2024-11222 | Medium / 6.4 | CE/EE | Merge-request pipeline race condition may permit actions in another user’s commit context |
| CVE-2026-12910 | Medium / 5.4 | CE/EE | Authenticated users may bypass SAML SSO sign-in restrictions |
| CVE-2026-82837 | Medium / 5.3 | CE/EE | Workhorse senddata emitters may expose sensitive credentials or tokens |
| CVE-2026-19619 | Medium / 4.7 | CE/EE | Content Editor HTML sanitization issue enables JavaScript execution in a target session |
| CVE-2026-86341 | Medium / 4.4 | EE | Owners or Maintainers could disable protected-environment approval requirements |
| CVE-2026-86340 | Medium / 4.4 | EE | Deleting the sole approver can bypass protected-environment deployment approvals |
| CVE-2026-7514 | Medium / 4.3 | CE/EE | Developers may replace Generic Package Registry content and hide packages |
| CVE-2026-8030 | Medium / 4.3 | CE/EE | Namespace-transfer validation flaw can prevent group-setting modifications |
| CVE-2026-16794 | Medium / 4.3 | EE | Security Managers may execute CI/CD jobs and access protected group-project variables |
| CVE-2026-3855 | Low / 3.1 | CE/EE | Terraform State API flaw may disclose restricted files or cause denial of service |
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to…