Vulnerability

CISA flags critical GitLab path‑traversal bug as actively exploited

⏱️ 3 min read📅 9/14/2026👁️ 17 views

Why this matters now

CISA has officially listed CVE‑2026‑85706 as an actively exploited vulnerability and, under Binding Operational Directive 26‑04, gave federal agencies just three days to apply the fix.

Technical snapshot

The flaw lives in GitLab’s repository‑commits API. Missing authentication enforcement combined with improper path confinement lets anyone read credentials and other sensitive files without logging in.

In practice, an unauthenticated request can traverse the repository structure and dump data that should be behind access controls.

Patch status

GitLab responded quickly. Fixed versions are:

  • Community Edition & Enterprise Edition 19.3.2
  • 19.2.6
  • 19.1

Organizations still running older releases are exposed.

Threat activity on the wire

watchTowr reported a spike in Internet probes targeting unpatched GitLab instances for this exact CVE. The scans are blunt – they simply ask the vulnerable endpoint for data and watch for a response.

Broader GitLab history

This isn’t the first time GitLab has landed on CISA’s radar. Since November 2021, four GitLab flaws have been tagged as actively exploited, including CVE‑2021‑22175 and CVE‑2021‑39935. Earlier this year, a high‑severity two‑factor authentication bypass was also patched.

Who needs to act

All federal agencies must patch within the three‑day window. CISA explicitly urged private‑sector organisations to follow suit – the risk isn’t limited to government.

Immediate defensive steps

  1. Verify your GitLab version. If you’re below 19.1, upgrade to the latest patched release.
  2. After patching, rotate any credentials that may have been read – especially service‑account tokens and SSH keys stored in repositories.
  3. Block external access to the repository‑commits API unless absolutely required. A firewall rule limiting source IPs can buy time.
  4. Enable audit logging and scan for anomalous read requests that match the probe pattern reported by watchTowr.
  5. Review MFA settings across all accounts; the January 2FA bypass shows that authentication layers can be bypassed.

Even if you’re not a federal agency, treating this as a high‑severity incident will keep your DevSecOps pipeline from becoming an easy data dump for opportunistic hackers.

#GitLab#CVE-2026-85706#CISA#patch#security advisory