GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Cybersecurity · September 12, 2026

Cybersecurity·thehackernews.com

GitLab has shipped patches for a maximum-severity flaw, CVE-2026-85706, a path traversal bug in the repository commits API that lets an unauthenticated attacker read arbitrary files from a vulnerable server. Scanning activity targeting the bug appeared within hours of the advisory going public, underscoring how fast attackers move once a CVSS 10.0 issue is disclosed. Admins running self-managed GitLab instances should apply the update without delay.

// source: thehackernews.com ↗

Back to Blog