THREAT OPS › Threat News › CVE-2026-85706 | GitLab CE/EE Repository Commits API Path Traversal Vulnerability
CVE-2026-85706 | GitLab CE/EE Repository Commits API Path Traversal Vulnerability
<p>CVE-2026-85706 is a critical path traversal vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerability exists in the repository commits API and, under certain conditions, allows an unauthenticated attacker to read arbitrary files from an affected GitLab server due to improper path confinement and missing authentication enforcement.</p> <p><a href="https
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-85706cve
Original source: https://horizon3.ai/attack-research/vulnerabilities/cve-2026-85706/