Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5968 articles · 214609 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2026-85706KEVEXPLOITEDPATCHED
GitLab · GitLab

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Affected Products

VendorProductVersions
GitLabGitLab18.7, 19.2, 19.3

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/627748
  • https://hackerone.com/reports/3909881(technical-description, exploit, permissions-required)

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-85706 | GitLab up to 19.1.7/19.2.5/19.3.1 Repository Commits API missing authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
19.1.819.2.619.3.2
CWECWE-22
PublishedSep 12, 2026
Last enriched3h ago
Trending Score139🔥
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 41
CRITICALCVE-2026-87719
Deserialization of Untrusted Data in GitLab
Trending: 41
HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 27
HIGHCVE-2026-18252
Inclusion of Functionality from Untrusted Control Sphere in GitLab
Trending: 5
HIGHCVE-2026-75871
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an a
Trending: 4

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 12, 2026
Added to CISA KEV
Sep 12, 2026
Discovered by ZDM
Sep 12, 2026
Actively Exploited
Sep 12, 2026
Patch Available
Sep 12, 2026