HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Path Traversal in GitLab (CVE‑2026‑85706) Threatens Software Supply Chains

GitLab CE and EE contain a CVSS 10.0 path‑traversal flaw (CVE‑2026‑85706) that lets unauthenticated attackers read or write arbitrary files, potentially injecting malicious code into repositories. The issue highlights the need for continuous supply‑chain risk controls and auditable evidence of remediation.

Verisq™ Intelligence · 📅 September 14, 2026 · 📰 darkreading.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
darkreading.com

Critical Path Traversal in GitLab (CVE‑2026‑85706) Threatens Software Supply Chains

What It Is — CVE‑2026‑85706 is a path‑traversal flaw in GitLab Community Edition and Enterprise Edition that lets an unauthenticated attacker read or write arbitrary files on the host. The vulnerability carries a CVSS 3.1 base score of 10.0 (critical).

Exploitability — Public proof‑of‑concept code is available; no confirmed wild‑use yet, but the remote, unauthenticated nature makes exploitation highly probable.

Affected Products — Self‑hosted GitLab CE and EE versions prior to the vendor‑issued patch (released 2026‑09‑10).

Why It Matters for Trust & Control Assurance

  • A compromised repository can become a conduit for malicious code, breaking the integrity of downstream software supply chains.
  • Continuous monitoring of repository access controls and auditable evidence of timely patching are essential to demonstrate due‑diligence to auditors and partners.
  • Demonstrable supply‑chain risk management aligns with enterprise‑buyer expectations for defensible, control‑based assurance.

Recommended Actions

  1. Apply GitLab’s security patch immediately.
  2. Verify that file‑system permissions and web‑server settings block path traversal.
  3. Capture evidence of patch deployment and configuration state in a control‑mapping repository.
  4. Review and tighten supply‑chain risk controls, ensuring audit‑ready logs of repository changes.

Source: Dark Reading

📰 Original Source
https://www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →