THREATOPS
THREAT OPSThreat News › Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediately

Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediately

medorca_securityPublished 2026-09-14

<p>Executive Summary A critical vulnerability (CVE-2026-85706, CVSS 10.0) was disclosed affecting GitLab CE and EE self-managed instances, allowing attackers to read arbitrary server files without authentication via a single HTTP request to the commits API. Due to the potential for complete infrastructure compromise through exposed secrets, immediate patching is required. About CVE-2026-85706 The

Indicators of compromise

Original source: https://orca.security/resources/blog/gitlab-critical-path-traversal-cve-2026-85706-exploited/