THREAT OPS › Threat News › Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediately
Breaking: GitLab Critical Path Traversal Flaw Exploited in the Wild — Patch Immediately
<p>Executive Summary A critical vulnerability (CVE-2026-85706, CVSS 10.0) was disclosed affecting GitLab CE and EE self-managed instances, allowing attackers to read arbitrary server files without authentication via a single HTTP request to the commits API. Due to the potential for complete infrastructure compromise through exposed secrets, immediate patching is required. About CVE-2026-85706 The
Indicators of compromise
- CVE-2026-85706cve