GitLab vulnerability

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Published 12 Sep 2026Updated 12 Sep 2026187 sources
CVSS 10.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Affected versions

GitLab: 18.7 through before 19.1.8 (semver); 19.2 through before 19.2.6 (semver); 19.3 through before 19.3.2 (semver) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

RepositoryAuthorFirst seenReference
SploitusUnauthenticated file read in GitLab CE/EE via Workhorse path-encoding bypass enabling shell access.ynsmroztas2026-09-11T21:29:53Verifiedynsmroztas/GitLabSniperCVE-2026-85706 Unauthenticated File Read★ 7ynsmroztas2026-09-11CandidateSploitusProof-of-concept exploit for CVE-2026-85706. CVSS 10.Sploitus index2026-09-12T10:43:12+00:00CandidateSploitusUnauthenticated arbitrary file read in GitLab CE/EE 18.7-19.3.1 via Workhorse/Puma encoding mismatch.0xlyvio2026-09-12T20:42:11Verified0xlyvio/cve-2026-85706-poc-exploit-gitlabUnauthenticated arbitrary file read in GitLab CE/EE 18.7-19.3.1 via Workhorse/Puma encoding mismatch.0xlyvio2026-09-12T20:42:11Verifiedjithinkrishnanrs/gitlab-cve-2026-85706-iocCVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules.★ 1jithinkrishnanrs2026-09-12Verifiedsolivaquaant/CVE-2026-85706PoC for CVE-2026-85706: GitLab CE/EE unauthenticated arbitrary local file read★ 0solivaquaant2026-09-11Verifiedmhtsec/CVE-2026-85706GitLab CE/EE unauthenticated path traversal (CVE-2026-85706) - PoC★ 3mhtsec2026-09-11Verifiedguneykabel/cve-2026-85706Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1★ 23guneykabel2026-09-11VerifiedFlowerWitch/CVE-2026-85706_docker_expCVE-2026-85706_docker_exp★ 1FlowerWitch2026-09-11Verified