ZeroDayAlert

CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

GitLab Community Edition and Enterprise Edition Added to KEV 2026-09-11 Federal due 2026-09-14 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

GitLab Community Edition and Enterprise Edition instances are vulnerable to unauthenticated path traversal attacks against the repository commits API. An unauthenticated user can exploit improper path confinement and missing authentication checks to read arbitrary files from the affected system. The record does not specify which versions or deployment configurations are in scope.

How to check whether this touches you

  • Inventory any GitLab Community or Enterprise Edition deployments you operate, including self-hosted and cloud-hosted instances.
  • Determine whether each instance's repository commits API is reachable without authentication—test unauthenticated access from outside your network if possible, or review network ingress rules and reverse proxy configuration.
  • Establish the running version number from the GitLab admin panel or command line; version fingerprints are a starting signal but do not confirm patch status, as some deployments receive backported fixes outside the standard release cycle.
  • Review GitLab's published advisory to confirm which versions are affected and which patches or workarounds are available.
  • If you cannot determine exposure quickly, assume the instance is reachable and requires immediate attention.

What to do

  1. Review GitLab's official security advisory and apply the vendor's recommended mitigations or patches without delay, in line with CISA BOD 26-04 timelines (remediation due 2026-09-14).
  2. If patching is not immediately possible, restrict network access to the repository commits API endpoint—use firewall rules, reverse proxy authentication, or IP allowlisting to block unauthenticated requests.
  3. Enable detailed logging on the repository commits API and check for access patterns that suggest attempted file reads outside the expected commit path structure.
  4. If your deployment is cloud-hosted and the vendor cannot provide a patch or workaround, evaluate discontinuation of the service in accordance with BOD 26-04 guidance.
  5. Escalate to your security team and change control board if the instance is internet-facing or processes sensitive source code.

If you find you were exposed

Check your GitLab API access logs and web server logs from at least 90 days before the vulnerability was added to the CISA catalogue (2026-09-11) for anomalous requests to commit endpoints, particularly those using path traversal sequences (../, ..\\, or encoded variants) or attempts to access files outside the repository tree. Exploitation typically occurs before public disclosure, so retention of historical logs is essential to confirm whether an attacker accessed sensitive files such as configuration, secrets, or user data.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-85706 is being exploited. It cannot tell you whether Community Edition and Enterprise Edition is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →