GitLab Critical Path Traversal Vulnerability Patch Needed

www.news4hackers.com-gitlab-critical-path-traversal-vulnerability-patch-needed-gitlab-critical-path-traversal-vulnerability-patch-needed

GitLab issued an urgent advisory on Thursday, urging administrators to apply patches immediately to mitigate a critical path traversal vulnerability designated as CVE-2026-85706.

Urgent Advisory and Vulnerability Details

The flaw, identified by a security researcher operating under the username ‘s3ntago’ and disclosed through GitLab’s HackerOne program, arises from insufficient path validation and inadequate authentication controls within the repository commits API.

Attackers exploiting this issue can access unauthorized data, including credentials, secrets, and confidential information, under specific conditions without requiring authentication.

Exploitation and Detection

Although GitLab has not confirmed active exploitation of the vulnerability, cybersecurity firm watchTowr reported that malicious actors are already scanning internet-facing GitLab instances for systems vulnerable to CVE-2026-85706.

\”Defenders must scrutinize log files for HTTP POST requests targeting ‘/api/v4/projects/{id}/repository/commits/’ endpoints with ‘file.path’ parameters to detect potential breaches,\” watchTowr advised.

This follows the recent resolution of another critical flaw, CVE-2026-87719, which stemmed from an insecure deserialization vulnerability in the GraphQL subscription serializer.

Recent Security Updates

Patches for both vulnerabilities were released in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1.

The company emphasized that all self-managed installations must update promptly, stating, \”These versions include essential security updates, and immediate migration is strongly recommended.\” GitLab.com and GitLab Dedicated customers are already protected.

Historical Context and Ongoing Threats

This incident adds to a series of path traversal vulnerabilities impacting GitLab. In May 2023, CVE-2023-2825 exposed sensitive data on unpatched servers, prompting warnings from CISA and the FBI about the persistence of such flaws since 2007.

Earlier this year, GitLab addressed a high-severity two-factor authentication bypass affecting both community and enterprise editions. CISA has previously flagged four GitLab vulnerabilities as actively exploited, including CVE-2021-22175 and CVE-2021-39935 in February 2026.

Conclusion

The GitLab DevSecOps platform, utilized by over 30 million users, remains a target for attackers seeking to exploit misconfigurations and outdated systems. Update September 11, 09:39 EDT: Additional details added regarding watchTowr’s findings on CVE-2026-85706 reconnaissance activities.



About Author

en_USEnglish