Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Ivanti EPMM CVE-2023-35078 Flaw Lets Attackers Access Devices
September 11, 2026
Okta Patches Critical Auth0 and Access Gateway Flaws
September 11, 2026
Critical JFrog Artifactory Vulnerabilities Actively Exploited
September 11, 2026
Home/CyberSecurity News/GitLab Patches Critical RCE, Credential Theft, and File Read Vulnerabilities
CyberSecurity News

GitLab Patches Critical RCE, Credential Theft, and File Read Vulnerabilities

Key Takeaways GitLab has released urgent security updates addressing multiple critical vulnerabilities across its Community and Enterprise Editions. Two critical flaws, CVE-2026-85706 and...

David kimber
David kimber
September 11, 2026 3 Min Read
3 0

Key Takeaways

  • GitLab has released urgent security updates addressing multiple critical vulnerabilities across its Community and Enterprise Editions.
  • Two critical flaws, CVE-2026-85706 and CVE-2026-87719, could lead to unauthenticated arbitrary file reads and credential theft, respectively.
  • A high-severity remote code execution (RCE) vulnerability, CVE-2026-88765, also affects GitLab Enterprise Edition.
  • Self-managed GitLab customers are strongly advised to update immediately to versions 19.3.2, 19.2.6, or 19.1.8.

GitLab has deployed crucial security updates for its Community Edition (CE) and Enterprise Edition (EE) platforms, addressing a series of vulnerabilities that include two critical flaws enabling arbitrary file reads and credential theft. Additionally, a high-severity issue in GitLab EE could permit authenticated attackers to achieve remote code execution (RCE).

Table Of Content

  • Key Takeaways
  • Critical Arbitrary File Read Vulnerability (CVE-2026-85706)
  • Critical Credential Theft Vulnerability (CVE-2026-87719)
  • High-Severity Remote Code Execution (CVE-2026-88765)
  • What You Should Do

The company released patched versions 19.3.2, 19.2.6, and 19.1.8 on September 10, 2026, urging all self-managed customers to apply these updates without delay. GitLab.com instances are already running the secured releases, while GitLab Dedicated customers are not required to take any action.

Critical Arbitrary File Read Vulnerability (CVE-2026-85706)

The most severe vulnerability identified is CVE-2026-85706, a path traversal flaw residing within the repository commits API, impacting both GitLab CE and EE. This critical issue received a CVSS score of 10.0, indicating maximum severity. According to GitLab, this flaw could allow an unauthenticated attacker, under specific conditions, to read any file from an affected GitLab server.

The root cause of this vulnerability lies in improper path confinement combined with a lack of authentication enforcement within the repository commits API. An attacker could craft specific path traversal sequences to access files located outside the intended repository directory. Depending on the server’s configuration, this could expose sensitive data such as application settings, secrets, tokens, SSH keys, or database credentials accessible by the GitLab process.

CVE-2026-85706 affects GitLab CE and EE versions 18.7 through 19.1.7, versions 19.2 before 19.2.6, and versions 19.3 before 19.3.2. Security researcher s3ntago was credited with reporting this vulnerability through GitLab’s HackerOne bug bounty program.

Critical Credential Theft Vulnerability (CVE-2026-87719)

Another critical vulnerability, CVE-2026-87719, was patched, stemming from an insecure deserialization flaw in the GraphQL subscription serializer specific to GitLab EE. This issue carries a CVSS score of 9.9 and requires an authenticated user with Duo Chat access to exploit.

According to GitLab, an attacker could submit a specially crafted GraphQL subscription argument. This manipulation could bypass serialization controls, triggering a server-side object lookup that ultimately exposes Advanced Search instance configurations and other sensitive credentials. This flaw impacts GitLab EE versions from 18.3 before 19.1.8, versions 19.2 before 19.2.6, and versions 19.3 before 19.3.2.

High-Severity Remote Code Execution (CVE-2026-88765)

A third significant vulnerability, CVE-2026-88765, is a buffer overflow found in GitLab EE’s Unicode conversion wrapper. Rated with a CVSS score of 8.5, this flaw could enable an authenticated attacker to execute arbitrary code remotely by importing a specially crafted Git project export. The overflow occurs during Advanced Search indexing, making any system that allows project imports a potential target.

In addition to these major vulnerabilities, GitLab also addressed several other high-severity issues. These included flaws affecting protected CI/CD variables, Markdown rendering, CI/CD environment variable access, and GraphQL resource handling. These vulnerabilities could potentially allow lower-privileged users to access protected variables, initiate unintended state-changing requests, or lead to denial-of-service conditions.

Administrators should upgrade to GitLab 19.3.2, 19.2.6, or 19.1.8, depending on their current supported release branch. It is important to note that these updates involve database migrations, which will result in downtime for single-node deployments until the migrations are complete. Multi-node deployments, if properly configured, can leverage GitLab’s zero-downtime upgrade process.

What You Should Do

  • Immediately Update: All self-managed GitLab CE and EE customers must update their instances to versions 19.3.2, 19.2.6, or 19.1.8 as soon as possible.
  • Review Upgrade Procedures: Be aware that single-node deployments will experience downtime during database migrations. Plan accordingly.
  • Verify Multi-Node Configuration: For multi-node deployments, ensure your zero-downtime upgrade process is correctly configured before initiating the update.
  • Monitor for Anomalies: After applying patches, monitor your GitLab instances for any unusual activity or access attempts, especially concerning file reads or project imports.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEHackerPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

New attack vector: Adversarial machine learning hides AI commands in plain text

Next Post

Critical JFrog Artifactory Vulnerabilities Actively Exploited

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Best Enterprise Browsers for 2026
September 11, 2026
Top Cloud Security Posture Management (CSPM) Tools for 2026
September 11, 2026
Top Cloud Workload Protection Solutions for 2026
September 11, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us