$ techbeacon▋
CVE & Exploits

GitLab Faces Immediate Threat as Critical Path‑Traversal Bug Is Actively Exploited

GitLab Faces Immediate Threat as Critical Path‑Traversal Bug Is Actively Exploited

Security researchers observed active exploitation of a critical GitLab vulnerability just hours after the company disclosed it on September 10, 2026. The flaw, catalogued as CVE-2026-85706, carries a perfect CVSS rating of 10.0 and enables unauthenticated attackers to read arbitrary files on affected servers through a single HTTP request to the repository commits API.

The vulnerability stems from insufficient validation of file paths supplied to the commits endpoint, allowing a crafted request to traverse directories beyond the intended scope. By leveraging this weakness, an attacker can retrieve configuration files, source code, or any data the GitLab instance stores, potentially exposing secrets, credentials, and proprietary code.

Within 24 hours of the public advisory, threat actors began probing vulnerable installations, as reported by security outlet Security Affairs. Early indicators suggest the exploitation is automated, targeting a broad range of self‑hosted GitLab deployments that have not yet applied the forthcoming fix. Organizations that expose GitLab to the internet without additional hardening measures are especially at risk.

GitLab responded by releasing an emergency patch and urging users to upgrade immediately. The company also recommended disabling the commits API temporarily, tightening network access controls, and monitoring logs for unusual file‑read requests. Administrators are advised to verify that all instances run the patched version and to audit any files that may have been accessed during the brief window of exposure.

The incident underscores the broader challenge of securing development platforms that serve as central repositories for code and sensitive assets. As software supply‑chain attacks grow in frequency, a single high‑severity flaw can have cascading effects across multiple projects and organizations. Analysts expect that the rapid exploitation of CVE-2026-85706 will prompt a renewed focus on timely patch management and stricter API security practices across the industry.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related