Vulnerability
Published 2026-09-10
Verified 2026-09-19

GitLab CE/EE path traversal CVE-2026-85706 (CVSS 10); watchTowr sees probes day after patch

GitLab Critical Patch Release (10 September 2026) ships CE/EE 19.3.2, 19.2.6 and 19.1.8. CVE-2026-85706 is a Critical path traversal in the repository commits API (improper path confinement plus missing authentication enforcement) that can let an unauthenticated requester read arbitrary files from the GitLab server under certain conditions. GitLab CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). Impacted: CE/EE from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Reported via HackerOne by s3ntago. Same release also fixes CVE-2026-87719 (EE GraphQL subscription serializer insecure deserialization; authenticated Duo Chat user; CVSS 9.9) plus further High issues. GitLab.com is patched; Dedicated customers need no action; self-managed must upgrade immediately. NEW 11 September 2026: watchTowr reports in-the-wild probes for CVE-2026-85706 within a day of disclosure (POST /api/v4/projects/{id}/repository/commits/ with file.path). Hunt those log lines. Primary: GitLab docs patch release; secondary: watchTowr / SecurityWeek / BleepingComputer. UPDATE 11 September 2026: CISA added CVE-2026-85706 to KEV (dateAdded 2026-09-11; catalogVersion 2026.09.11). Self-managed instances that have not taken 19.3.2 / 19.2.6 / 19.1.8 should treat this as actively exploited and patch immediately.

Product
GitLab Community Edition and Enterprise Edition (repository commits API; EE GraphQL Duo Chat path for CVE-2026-87719)
Versions
CVE-2026-85706: CE/EE 18.7 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2. CVE-2026-87719: EE 18.3 before 19.1.8 / 19.2 before 19.2.6 / 19.3 before 19.3.2
CVSS
(CVE-2026-85706); 9.9 (CVE-2026-87719, EE)
Exploited in Australia?
unknown
Patch to
Upgrade self-managed GitLab to 19.1.8 / 19.2.6 / 19.3.2 (or later); hunt commits-API file.path POSTs

Primary: GitLab Critical Patch Release 19.3.2 / 19.2.6 / 19.1.8 (10 Sep 2026) · Vendor: GitLab Docs — security fixes · CVE: CVE-2026-85706, CVE-2026-87719 · watchTowr rapid reaction (11 Sep 2026); also SecurityWeek / BleepingComputer

vulnerabilities cloud identity