A recently disclosed vulnerability (CVE-2026-85706) affects GitLab Community Edition (CE) and Enterprise Edition (EE) and may allow an unauthenticated remote attacker to read arbitrary files from the GitLab server, potentially exposing credentials, secrets, and other sensitive information. Severity level: CVSS Score: 10/Critical. Description: CVE-2026-85706 is a critical path traversal vulnerability in GitLab's Repository Commits API. The flaw results from improper path confinement and missing authentication enforcement, allowing an unauthenticated attacker to submit a specially crafted request and read arbitrary files from the GitLab server. Sensitive information such as SSH keys, credentials, configuration files, CI/CD secrets, and access tokens may be exposed. Affected Versions:
GitLab CE/EE 18.7 through 19.1.7
GitLab CE/EE 19.2.0 through 19.2.5
GitLab CE/EE 19.3.0 through 19.3.1
Impact: Successful exploitation may allow attackers to read arbitrary files from the GitLab server. Resolution: Upgrade GitLab immediately to the following fixed versions:-
A recently disclosed vulnerability (CVE-2026-85706) affects GitLab Community Edition (CE) and Enterprise Edition (EE) and may allow an unauthenticated remote attacker to read arbitrary files from the GitLab server, potentially exposing credentials, secrets, and other sensitive information. Severity level: CVSS Score: 10/Critical. Description: CVE-2026-85706 is a critical path traversal vulnerability in GitLab's Repository Commits API. The flaw results from improper path confinement and missing authentication enforcement, allowing an unauthenticated attacker to submit a specially crafted request and read arbitrary files from the GitLab server. Sensitive information such as SSH keys, credentials, configuration files, CI/CD secrets, and access tokens may be exposed. Affected Versions:
GitLab CE/EE 18.7 through 19.1.7
GitLab CE/EE 19.2.0 through 19.2.5
GitLab CE/EE 19.3.0 through 19.3.1
Impact: Successful exploitation may allow attackers to read arbitrary files from the GitLab server. Resolution: Upgrade GitLab immediately to the following fixed versions:-