Image: offsec.com · rights & removal
CVE-2026-85706: GitLab Unauthenticated Arbitrary File Read via the Repository Commits API
Reporting by Offensive Security BlogRead the original at offsec.com
Executive Summary
Facts Only
* CVE ID: CVE-2026-85706.
* Vulnerability type: Unauthenticated path traversal in GitLab repository commits/files API.
* Affected products: GitLab Community Edition (CE) and Enterprise Edition (EE).
* Affected component: Repository Commits API / Files API, routed via GitLab Workhorse body-upload.
* Vulnerability cause: File referenced by a request-supplied path is opened before authentication and without proper confinement to the repository directory.
* Impact: Unauthenticated arbitrary file read on the GitLab server.
* Affected versions and fixed releases: 18.7 up to (not including) 19.1.8; 19.2.0 up to (not including) 19.2.6; 19.3.0 up to (not including) 19.3.2.
* CVSS Score: 10.0.
* Attack Vector: Network.
* Authentication requirement: Not required for exploitation.
* Affected instances: Self-managed GitLab CE and EE; GitLab.com and GitLab Dedicated are not affected.
Full Take
From the original · Offensive Security Blog
Sep 28, 2026 CVE-2026-85706: GitLab Unauthenticated Arbitrary File Read via the Repository Commits API CVE-2026-85706 is a critical, unauthenticated path traversal vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). CVE-2026-85706 is a critical, unauthenticated path traversal vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE).Read the full story at offsec.com
Sentinel — Human
This text reads as a highly focused, authoritative security advisory, likely written by or heavily edited by an expert, presenting raw technical facts in a structured manner designed for immediate operational response.
