← Back to Feed

GitLab urges users to patch max severity path traversal flaw

CVE-2026-85706

September 11, 2026 · BleepingComputer · Severity: HIGH

GitLab has disclosed a maximum severity path traversal vulnerability, CVE-2026-85706, that affects both Community and Enterprise Edition servers, allowing attackers to read arbitrary files. The company has released patches and strongly recommends immediate upgrades to prevent data exposure.

Key Takeaways

  • GitLab has disclosed a maximum severity path traversal vulnerability, CVE-2026-85706, that allows attackers to read arbitrary files on both Community and Enterprise Edition servers. The flaw poses a critical risk to data confidentiality and system integrity. GitLab strongly urges all users to apply the available patches immediately to prevent exploitation.
  • This path traversal flaw enables unauthorized reading of sensitive files, potentially exposing proprietary code, credentials, and configuration details. Attackers require no special privileges, only network access to the affected GitLab instance. Organizations running unpatched versions are at high risk of data breaches.
  • GitLab has released security updates for all supported versions to address CVE-2026-85706. System administrators should prioritize upgrading their GitLab installations as soon as possible. Delaying the patch increases the window of opportunity for attackers to steal sensitive information.
☕ Buy a Coffee