GitLab patches critical path traversal vulnerability CVE-2026-85706

GitLab released urgent patches on September 11, 2026 to address CVE-2026-85706 (CVSS 10.0), a maximum-severity path traversal flaw in the repository commits API affecting self-managed installations. The vulnerability allows unauthenticated attackers to read arbitrary files; CISA added it to the exploited vulnerabilities catalog with active in-the-wild probes within days.

5 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825. https://www. bleepingcomputer.com/news/secu rity/git

mastodon:infosec-exchangeother18d ago kagi ↗

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825. https://www. bleepingcomputer.com/news/secu rity/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/

🤖 CVE-2026-85706 (maximum severity): path traversal vulnerability in GitLab CE/EE. GitLab urges admins to patch their servers immediately. Security release required to remediate. 🔗 https://www. blee

mastodon:infosec-exchangeother18d ago kagi ↗

🤖 CVE-2026-85706 (maximum severity): path traversal vulnerability in GitLab CE/EE. GitLab urges admins to patch their servers immediately. Security release required to remediate. 🔗 https://www. bleepingcomputer.com/news/secu rity/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/ # CVE # CyberSec # GitLab

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. https://www. bleepingcomputer.com/news/secu rity/gi

mastodon:infosec-exchangeother18d ago kagi ↗

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. https://www. bleepingcomputer.com/news/secu rity/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/