rootpwn

Advisories

GitLab Urges Immediate Patch for CVE‑2026‑85706 Path Traversal Flaw – Attackers Already Scanning

GitLab has released critical security updates for two high‑severity bugs: CVE‑2026‑85706, an unauthenticated path traversal that can expose arbitrary files, and CVE‑2026‑87719, an insecure deserialization flaw that lets privileged users harvest credentials. The first flaw was discovered by researcher s3ntago via GitLab’s HackerOne program, and watchdog firm watchTowr reports attackers are already probing exposed instances. All self‑managed GitLab installations must upgrade to the patched 19.3.2/19.2.6/19.1 releases immediately. The platform serves over 30 million users, including more than 50%

GitLab’s latest advisory warns that a newly identified path‑traversal vulnerability (CVE‑2026‑85706) allows unauthenticated attackers to read any file on a vulnerable server when the repository commits API is used under certain conditions. The flaw stems from missing path confinement and authentication checks.

In‑the‑Wild Activity

Cyber‑security firm watchTowr has already detected probing traffic targeting exposed GitLab instances that have not yet applied the patch. The probes look for single‑request exploits that can read arbitrary files via the /api/v4/projects/{id}/repository/commits/ endpoint.

"watchTowr Intel is already observing in‑the‑wild probes for the latest critical GitLab Path Traversal vulnerability, CVE‑2026‑85706, which allows attackers to read arbitrary files in a single HTTP request," the firm warned.

Second Critical Flaw: CVE‑2026‑87719

In addition to the path traversal issue, GitLab fixed an insecure deserialization vulnerability that could let authenticated users with Duo Chat access steal sensitive credentials and Advanced Search configuration data. This flaw affects GitLab Enterprise Edition and requires immediate remediation.

Patch Guidance

  • Upgrade all self‑managed GitLab installations to the patched versions: 19.3.2, 19.2.6, or 19.1.
  • GitLab.com is already running the updated code; Dedicated customers do not need to take action.
  • Hunt logs for POST requests to /api/v4/projects/{id}/repository/commits/ that include a file.path parameter to detect potential exploitation attempts.
  • Apply the patch as soon as possible – the window for indiscriminate exploitation is likely short.

Historical Context

GitLab has faced several high‑severity path traversal bugs in the past, including CVE‑2023‑2825, which exposed sensitive data on unpatched servers. CISA and the FBI have repeatedly warned that such flaws are “unforgivable” and must be eliminated before shipping. The platform’s widespread use—over 30 million users and more than 50% of Fortune 100 companies—underscores the urgency of these updates.

GitLab CVE-2026-85706 Path Traversal Patch DevSecOps

← All news