GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. This maximum-severity path traversal flaw carries a CVSS score of 10.0 and allows unauthenticated attackers to read arbitrary files via a single HTTP request to the commits-API. Malicious actors are actively exploiting the vulnerability to access sensitive files within software development environments. CISA and other security entities warn that these attacks are ongoing, urging immediate patching to prevent unauthorized data access.
Listen to Live Briefing
Real-time synthesized voice briefing · Live Feeds Desk
- ✓ The GitLab vulnerability has a CVSS score of 10.0.
- ✓ CISA has added the GitLab flaw to its Known Exploited Vulnerabilities catalog.
- ✓ Threat actors are actively exploiting this vulnerability.
- ✓ The flaw allows unauthenticated users to access sensitive files from software-development environments.
What changed
CISA officially listed the GitLab vulnerability in its Known Exploited Vulnerabilities catalog.
Live updates
-
CISA Adds Critical GitLab File-Read Flaw to Known Exploited Vulnerabilities List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. This maximum-severity path traversal flaw carries a CVSS score of 10.0 and allows unauthenticated attackers to read arbitrary files via a single HTTP request to the commits-API. Malicious actors are actively exploiting the vulnerability to access sensitive files within software development environments. CISA and other security entities warn that these attacks are ongoing, urging immediate patching to prevent unauthorized data access.
Why it matters
The vulnerability targets the commits-API, making it accessible to anyone with network access to the instance. Because GitLab environments often house proprietary source code and secrets, this flaw poses a high risk of intellectual property theft.
What is confirmed
- The GitLab vulnerability has a CVSS score of 10.0.
- CISA has added the GitLab flaw to its Known Exploited Vulnerabilities catalog.
- Threat actors are actively exploiting this vulnerability.
- The flaw allows unauthenticated users to access sensitive files from software-development environments.
What to watch next
- Reports of specific data breaches resulting from the exploit
- GitLab updates on the number of affected installations
- Identification of specific threat actor groups targeting the flaw
confidence 100%Sources used for this update (4)
- www.yahoo.com — Malicious actors already using critical GitLab flaw, CISA and others warn
- www.infosecurity-magazine.com — Hackers Exploit Maximum Severity Flaw in GitLab
- securityaffairs.com — U.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog
- www.bleepingcomputer.com — CISA: Critical VMware RCE flaw now exploited by ransomware gangs
-
GitLab CVSS 10 Flaw Triggers In-the-Wild Probes
GitLab urges users to patch a maximum-severity path traversal vulnerability carrying a CVSS score of 10.0, identified as CVE-2026-85706. The flaw allows unauthenticated attackers to read arbitrary files using a single HTTP request via the commits-API. Within hours of disclosure, security researchers and threat actors initiated internet-wide probing and active exploitation of the vulnerability. The U.S. Cybersecurity and Infrastructure Security Agency warned that hackers are now exploiting the max severity GitLab flaw in attacks.
Why it matters
GitLab issued emergency security updates to address the unauthenticated file-read vulnerability affecting its platform. The rapid transition from disclosure to active exploitation highlights the speed at which threat actors weaponize critical API flaws. Organizations utilizing GitLab are instructed to apply patches immediately to prevent system compromise.
What is confirmed
- GitLab patched a maximum-severity path traversal vulnerability assigned CVE-2026-85706 with a CVSS score of 10.0.
- The vulnerability allows unauthenticated full file read via a single HTTP request through the commits-API.
- The U.S. Cybersecurity and Infrastructure Security Agency warned that hackers are now exploiting the max severity GitLab flaw in attacks.
What to watch next
- Additional CISA advisories or emergency directives regarding CVE-2026-85706
- Reports of specific enterprise compromises stemming from the commits-API flaw
- Release of automated patch adoption statistics from the GitLab ecosystem
confidence 100%Sources used for this update (10)
- The Hacker News — GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
- BleepingComputer — GitLab urges users to patch max severity path traversal flaw
- watchTowr — Rapid Reaction: GitLab Path Traversal Vulnerability (CVE-2026-85706)
- forkast.news — One HTTP Request, Every File on the Server: GitLab’s CVSS 10 Commits-API Flaw Hits Active Exploitation Within Hours
- CyberScoop — GitLab’s critical flaw is already drawing internet-wide probes
- Field Effect — GitLab fixes critical vulnerability as internet-wide probing begins
- linkedin.com — GitLab Issues Emergency Security Update For Maximum-Severity Vulnerability
- www.bleepingcomputer.com — CISA: Hackers now exploit max severity GitLab flaw in attacks
- cybersecuritynews.com — Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system
- securityaffairs.com — GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Community Sentiment: How do you assess this situation?
Voice your perspective · Real-time aggregated sentiment from the Live Feeds community