Back to advisories

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab patched a CVSS 10.0 unauthenticated file-read vulnerability (CVE-2026-85706) in the repository commits API that allows attackers to read arbitrary files from affected servers. In-the-wild probes are already active. Attackers can extract credentials, SSH keys, and other sensitive data without authentication.

CRITICALAdvisorySep 12, 2026
Action required
Immediately patch all GitLab instances to the latest patched version. If you cannot patch within 24 hours, restrict API access to the repository commits endpoint to authenticated users only and monitor logs for CVE-2026-85706 exploitation attempts.
Affected products
GitLab Community EditionGitLab Enterprise EditionGitLab