GitLab CVSS 10 Path Traversal Flaw Draws In-the-Wild Probes Within Hours
What happened
GitLab shipped an emergency patch release (versions 19.3.2, 19.2.6, and 19.1.8) fixing a maximum-severity path traversal vulnerability in the repository commits API, tracked as CVE-2026-85706 with a CVSS score of 10.0. The root cause is improper path confinement combined with missing authentication enforcement on that API endpoint, which allows a request crafted with a manipulated file path parameter to escape the intended repository directory and read arbitrary files from the underlying server file system. Independent researchers at watchTowr reported observing in-the-wild scanning for vulnerable, internet-exposed GitLab instances beginning within hours of the public disclosure, and CISA subsequently added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. The same patch train also closes a second critical issue, CVE-2026-87719 (CVSS 9.9), an insecure deserialization bug in the GraphQL subscription serializer that can expose Advanced Search configuration data and credentials to authenticated users with Duo Chat access.
Who is affected
Any self-managed GitLab Community Edition (CE) or Enterprise Edition (EE) instance running a version in the following ranges is exposed: 18.7 up to but not including 19.1.8, 19.2 up to but not including 19.2.6, and 19.3 up to but not including 19.3.2. GitLab.com is already running the patched release, and GitLab Dedicated customers do not need to take action. Exploitation of CVE-2026-85706 reportedly requires only that at least one public project exist on the instance, which is a very low bar for many organizations running internal developer platforms with mixed public and private repositories.
Why it matters
GitLab instances are a high-value target because they sit at the center of the software delivery lifecycle: source code, CI/CD variables and secrets, container registry credentials, and pipeline configuration all pass through them. A file-read primitive against an unauthenticated endpoint can be used to harvest configuration files, log files, and cached credentials, which in turn can be leveraged to move laterally into build pipelines and downstream systems. This is the second maximum or near-maximum severity GitLab vulnerability disclosed in recent weeks, and researchers note that the historical pattern for GitLab flaws has been a short window between disclosure and mass, indiscriminate exploitation attempts.
Technical details
- CVE-2026-85706 — CVSS 10.0. Path traversal in the repository commits API caused by improper path confinement and missing authentication enforcement. Allows unauthenticated file reads under certain conditions.
- CVE-2026-87719 — CVSS 9.9. Insecure deserialization in the GraphQL subscription serializer, exploitable by authenticated users with Duo Chat access to obtain Advanced Search configuration and sensitive credentials.
- Affected versions: GitLab CE/EE 18.7–19.1.7, 19.2–19.2.5, and 19.3–19.3.1.
- Fixed versions: 19.3.2, 19.2.6, and 19.1.8.
- Exploitation status: In-the-wild scanning confirmed by watchTowr starting roughly 06:00 UTC on the day of disclosure; CISA has added CVE-2026-85706 to its KEV catalog with a short remediation deadline for federal agencies.
Recommended actions
- Upgrade all self-managed GitLab CE/EE instances to 19.3.2, 19.2.6, or 19.1.8 immediately; treat this as an emergency change.
- If immediate patching is not possible, restrict or disable public access to projects and limit network exposure of the GitLab instance to trusted networks only.
- Review access and application logs for HTTP POST requests to
/api/v4/projects/{id}/repository/commits/endpoints containingfile.path-style parameters, which may indicate exploitation attempts. - Rotate CI/CD variables, deploy tokens, and any credentials that may have been stored in configuration or log files accessible via the vulnerable endpoint.
- Audit recent administrative and Duo Chat activity for signs of unauthorized access tied to CVE-2026-87719.
- Subscribe to GitLab's security release notifications and CISA's KEV catalog updates to track follow-on advisories.
Sources
- https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
- https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/
