Tech article
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure - thehackernews.com
Publisher description: GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.
NewsAPI | Sep 11, 2026 | The Hacker News
Automated excerpt
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10. 0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under certain conditions. The problem, per GitLab, stems from "improper path confinement and missing authentication enforcement in the repository commits API. " All versions from 18. 7 before 19. 1. 8, All versions from 19. 2 before 19. 2.
Selected automatically from source text; not independently written or fact-checked. Read the original for full context.