THREATOPS
THREAT OPSThreat News › CVE-2026-85706 | GitLab CE/EE Repository Commits API Path Traversal Vulnerability

CVE-2026-85706 | GitLab CE/EE Repository Commits API Path Traversal Vulnerability

medhorizon3Published 2026-09-11

<p>CVE-2026-85706 is a critical path traversal vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerability exists in the repository commits API and, under certain conditions, allows an unauthenticated attacker to read arbitrary files from an affected GitLab server due to improper path confinement and missing authentication enforcement.</p> <p><a href="https

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-85706/