GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Executive Summary
GitLab patched a critical CVE-2026-85706 (CVSS 10.0) path‑traversal flaw in its repository commits API that lets unauthenticated users read arbitrary server files. The vulnerability triggered in‑the‑wild probing within hours of public disclosure.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-11T16:30:18+00:00 - Category: cves
Original Description: GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
"To accomplish great things, we must not only act, but also dream; not only plan, but also believe."
— Anatole France