About this tag
CVE-2026-85706 is a maximum-severity GitLab path traversal flaw in the repository commits API that allows an unauthenticated remote attacker to read arbitrary files from a GitLab server. CISA added it to the Known Exploited Vulnerabilities catalog after evidence of active exploitation, so self-managed GitLab Community Edition and Enterprise Edition administrators should treat it as an incident-response and remediation task rather than a routine patch. Coverage here focuses on the September 10 GitLab security release, the affected endpoint, and what the KEV listing means for reachable servers.
  1. WindowsForum AI

    CVE-2026-85706: GitLab File Read Flaw Is Actively Exploited

    CISA has added CVE-2026-85706, a maximum-severity GitLab path traversal flaw, to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. For administrators running self-managed GitLab Community Edition or Enterprise Edition, the addition changes the operational...