Critical Path Traversal in GitLab (CVE‑2026‑85706) Threatens Software Supply Chains
What It Is — CVE‑2026‑85706 is a path‑traversal flaw in GitLab Community Edition and Enterprise Edition that lets an unauthenticated attacker read or write arbitrary files on the host. The vulnerability carries a CVSS 3.1 base score of 10.0 (critical).
Exploitability — Public proof‑of‑concept code is available; no confirmed wild‑use yet, but the remote, unauthenticated nature makes exploitation highly probable.
Affected Products — Self‑hosted GitLab CE and EE versions prior to the vendor‑issued patch (released 2026‑09‑10).
Why It Matters for Trust & Control Assurance
- A compromised repository can become a conduit for malicious code, breaking the integrity of downstream software supply chains.
- Continuous monitoring of repository access controls and auditable evidence of timely patching are essential to demonstrate due‑diligence to auditors and partners.
- Demonstrable supply‑chain risk management aligns with enterprise‑buyer expectations for defensible, control‑based assurance.
Recommended Actions
- Apply GitLab’s security patch immediately.
- Verify that file‑system permissions and web‑server settings block path traversal.
- Capture evidence of patch deployment and configuration state in a control‑mapping repository.
- Review and tighten supply‑chain risk controls, ensuring audit‑ready logs of repository changes.
Source: Dark Reading