CISA warns of active probing for GitLab path-traversal flaw CVE-2026-85706

1 min read
Source: BleepingComputer
CISA warns of active probing for GitLab path-traversal flaw CVE-2026-85706
Photo: BleepingComputer
TL;DR

CISA warns that attackers are probing for and could exploit CVE-2026-85706, a maximum-severity GitLab path-traversal flaw that allows unauthenticated access to credentials via the repository commits API. GitLab fixed the issue in CE/EE versions 19.3.2, 19.2.6, and 19.1, and organizations are urged to patch immediately as in-the-wild probes have been observed and the flaw was added to the actively exploited catalog.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer