GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab has patched CVE-2026-85706, a maximum-severity path traversal flaw in the repository commits API that is already seeing in-the-wild probing and could let unauthenticated attackers read arbitrary files from affected servers. The company also fixed CVE-2026-87719, a critical insecure deserialization issue in GitLab EE, and urged exposed self-managed instances to patch immediately or restrict public access. #GitLab #CVE-2026-85706 #CVE-2026-87719 #watchTowr

Keypoints

  • GitLab released fixes for multiple security flaws in Community Edition and Enterprise Edition.
  • CVE-2026-85706 is a critical path traversal bug in the repository commits API.
  • The flaw can allow unauthenticated attackers to read arbitrary files from GitLab servers.
  • watchTowr reported active probes against the vulnerability within hours of disclosure.
  • GitLab also patched CVE-2026-87719, an insecure deserialization issue affecting GitLab EE.

Read More: https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html