News

GitLab patches max-severity commits API file-read flaw

GitLab's 10 September 2026 critical patch release (19.3.2, 19.2.6, 19.1.8) fixes CVE-2026-85706, a CVSS 10.0 path traversal in the repository commits API affecting CE and EE from 18.7. GitLab.com is already patched. Dedicated needs no action. Self-managed must upgrade.

GitLab patches max-severity commits API file-read flaw

GitLab's critical patch release for 19.3.2, 19.2.6, and 19.1.8, posted 10 September 2026, leads with CVE-2026-85706. The advisory describes a path traversal in the repository commits API that, under certain conditions, could let an unauthenticated user read arbitrary files from the GitLab server.

This is GitLab's own critical patch release listing fixed CVEs and the patched version numbers. It is not a CISA advisory by itself.

The bug is rated CVSS 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). GitLab says the cause is improper path confinement plus missing authentication enforcement. s3ntago reported it via HackerOne. Impacted builds are GitLab CE and EE, all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

GitLab.com is already running a patched version. GitLab Dedicated customers need no action. Self-managed operators are told to upgrade immediately to 19.1.8, 19.2.6, or 19.3.2.

The same release also patches CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer on GitLab EE, rated CVSS 9.9. That path needs an authenticated Duo Chat user.

The Hacker News said watchTowr observed in-the-wild probes from 06:00 UTC on 11 September 2026, including file reads of logs and config for secrets. Those reports describe scanning, not a confirmed mass compromise in every environment. OpenCVE lists CVE-2026-85706 in the Known Exploited Vulnerabilities catalog, with a due date of 14 September 2026.

This follows Cyberpresso's earlier note on GitLab's GraphQL CVE-2026-19478. Other patch-now items this week include Microsoft's September 2026 Patch Tuesday, Cisco Secure FMC under active exploit, and Check Point VPN certificate flaws at 9.8.

Self-managed operators on 18.7 through unpatched 19.x should upgrade to 19.1.8, 19.2.6, or 19.3.2 now and review whether the commits API was reachable from the internet during the exposure window.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free