← Browse

CVE-2026-85706

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS — probability of exploitation (30 days)
14.6%
96.5th percentile
CISA KEV
Listed
Added 2026-09-11 · patch by 2026-09-14
Weakness / dates
CWE-22
Published 2026-09-12 · modified 2026-09-14

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Affected

gitlab

References

Official: NVD · CVE.org