CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
Key Takeaways The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a GitLab path traversal vulnerability, CVE-2026-85706, confirming active...
Key Takeaways
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a GitLab path traversal vulnerability, CVE-2026-85706, confirming active exploitation in the wild.
- This severe flaw, rated 10.0 on the CVSS scale, affects GitLab Community Edition and Enterprise Edition and allows unauthenticated attackers to read arbitrary files.
- The vulnerability impacts specific versions across GitLab CE/EE 18.7 through 19.3.1 and requires immediate patching to versions 19.1.8, 19.2.6, 19.3.2, or later.
- CISA has added the flaw to its Known Exploited Vulnerabilities catalog and mandated a rapid remediation for federal agencies, highlighting the urgency for all organizations.
CISA Issues Urgent Warning for Actively Exploited GitLab Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated a critical warning regarding a severe path traversal vulnerability in GitLab, identified as CVE-2026-85706. The agency confirms that this flaw is actively being exploited by threat actors, prompting its inclusion in the Known Exploited Vulnerabilities (KEV) catalog.
Table Of Content
This high-severity issue impacts both GitLab Community Edition (CE) and Enterprise Edition (EE) deployments and has been assigned the maximum CVSS score of 10.0, indicating extreme risk.
Details of the Vulnerability
CVE-2026-85706 is categorized as a path traversal vulnerability residing within GitLab’s repository commits API. According to GitLab, specific conditions allow an attacker, without authentication, to bypass proper path confinement and authentication checks. This enables them to read arbitrary files from a vulnerable GitLab server.
Path traversal vulnerabilities arise when software fails to adequately sanitize or restrict file paths provided in requests. In this particular instance, successful exploitation permits an external attacker to navigate beyond the intended repository directory structure, accessing and retrieving files located elsewhere on the server.
The gravity of this exposure is amplified by its low barrier to entry: it does not necessitate an account, user interaction, or any prior access to the system, making it highly susceptible to internet-based attacks.
Affected Versions and Remediation
The vulnerability affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. Organizations managing self-hosted GitLab instances are strongly advised to immediately identify any exposed assets and upgrade to a patched version. The recommended upgrade paths are GitLab 19.1.8, 19.2.6, 19.3.2, or any subsequent supported release, depending on their current deployment branch.
CISA officially added this flaw to the KEV catalog on September 11, 2026, and mandated a remediation deadline of September 14, 2026, for all federal civilian executive branch agencies. Furthermore, the agency has designated this issue as requiring forensic triage under Binding Operational Directive 26-04, a directive that underscores the potential for systems to have been compromised prior to patching.
Potential Impact and Attribution
While CISA has yet to confirm ransomware deployment in connection with this vulnerability, GitLab servers represent prime targets for adversaries. These platforms frequently host sensitive data, including proprietary source code, critical CI/CD configurations, access tokens, and deployment scripts. The ability to disclose arbitrary files can provide attackers with credentials, secrets, configuration details, and other valuable intelligence to facilitate further intrusion activities.
GitLab acknowledged security researcher s3ntago for responsibly disclosing the vulnerability through its HackerOne bug bounty program. The weakness is associated with CWE-35, a common weakness enumeration category for improper limitation of pathname access, which describes vulnerabilities enabling attackers to access files outside of an intended restricted directory.
What You Should Do
- Prioritize Patching: Immediately apply the necessary updates to GitLab 19.1.8, 19.2.6, 19.3.2, or a later supported release for all affected GitLab CE/EE instances, especially internet-facing systems.
- Review Logs: Scrutinize GitLab and any reverse-proxy logs for unusual or suspicious requests to the repository commits API and investigate any unexpected file access patterns.
- Rotate Credentials: Following a thorough assessment of potential compromise, rotate any credentials, tokens, and secrets that might have been exposed.
- Conduct Forensic Triage: Assume potential compromise for vulnerable systems and initiate forensic analysis as recommended by CISA, particularly if patching was delayed.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.