GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
AI Summary
A critical path traversal vulnerability in GitLab, tracked as CVE-2026-85706 with a CVSS score of 10.0, has been actively exploited in the wild within hours of its public disclosure. The flaw exists in the repository commits API and allows unauthenticated attackers to read arbitrary files, including sensitive configuration files and credentials, provided at least one public project exists. The U.S. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by September 14, 2026. Another critical insecure deserialization flaw, CVE-2026-87719, was also patched in GitLab EE, which could allow authenticated users with Duo Chat access to extract sensitive instance configurations via a crafted GraphQL subscription.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | file.Path | Details → |