HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical CVE-2026-85706 Path Traversal in GitLab Enables Unauthenticated File Read

GitLab disclosed CVE‑2026‑85706, a CVSS 10.0 path‑traversal flaw in the Repository Commits API that lets unauthenticated actors read arbitrary server files. The issue underscores the need for robust file‑access controls and auditable evidence of enforcement for compliance readiness.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Critical Path‑Traversal (CVE‑2026‑85706) in GitLab Repository Commits API Allows Unauthenticated File Read

What It Is – GitLab disclosed a CVE‑2026‑85706 flaw in its Repository Commits API that permits an unauthenticated attacker to traverse directories and read arbitrary files from the server’s filesystem.

Exploitability – The vulnerability is rated CVSS 10.0 (Critical). Public proof‑of‑concept probes appeared within hours of disclosure, indicating active exploitation attempts.

Affected Products – GitLab Community Edition (CE) and Enterprise Edition (EE) versions prior to the September 2026 security release.

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in access‑control enforcement at the application layer; continuous monitoring of file‑access logs is needed to prove that only authorized users can read repository data.
  • Provides auditors with concrete evidence of a control failure; remediation and evidence collection satisfy a single VCF control objective that maps to many frameworks (e.g., NIST CSF 2.0 “Protect – Data Security”).
  • Enterprise buyers increasingly demand a defensible audit trail showing that file‑system access controls are enforced and that any deviation is detected in real time.

Recommended Actions

  1. Apply GitLab’s September 2026 security patches to all instances immediately.
  2. Verify the patch level via the GitLab version endpoint or package manager.
  3. Enable and centralize file‑access logging; correlate logs with identity data to detect unauthorized reads.
  4. Map the “unauthorized file access” control to your framework of record and capture evidence in the Trust Center.
  5. Conduct a post‑patch validation scan for residual path‑traversal vectors.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →