Urgent.News

What's breaking now, across thousands of outlets.

Tech

GitLab CVE-2026-85706: Why an Arbitrary File Read on a DevSecOps Platform Is a Credential Incident

GitLab CVE-2026-85706: Why an Arbitrary File Read on a DevSecOps Platform Is a Credential Incident GitLab released 19.3.2, 19.2.6 and 19.1.8 on September 10, 2026, fixing CVE-2026-85706. The vendor describes the issue as improper path restriction combined with missing authentication in the repository commits API. An unauthenticated attacker can, under specific conditions, read arbitrary files…

GitLab has released updates to address CVE-2026-85706, an arbitrary file read vulnerability on their DevSecOps platform. This issue arises due to improper path restriction and missing authentication in the repository commits API, allowing unauthenticated attackers to read arbitrary files from the server. The CVSS 3.1 base score for this vulnerability is 10.0, and CISA has added it to its Known Exploited Vulnerabilities catalog, confirming real-world exploitation.

The true risk of this vulnerability lies in the fact that the files GitLab processes can access often include sensitive credentials rather than just content. By exploiting this vulnerability, an attacker can obtain sensitive information such as instance secrets, database and cache passwords, Runner and container registry credentials, object storage keys, OAuth and webhook secrets, and deployment tokens or private keys used by automation.

While patching the vulnerability closes the original door, it does not invalidate the duplicated keys that attackers may have already used. GitLab has released updates for self-managed Community Edition and Enterprise Edition across three branches, while GitLab.com and Dedicated customers do not require updates as they were patched by the vendor.

Detecting exploitation in logs can be achieved by searching for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ with a file.path parameter.

Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Modelling The Real World: Object Oriented Programming

So far, functions have been the main way to organize code, break a problem into small, reusable pieces of logic. But some problems aren't just about logic; they're about things a customer, a bank…

  • Object-oriented programming organizes code into objects
  • Bundles data and behavior within single units
  • Simplifies managing complex entities

Warlock: Ransomware Deployment from SYSVOL After SharePoint Compromise

1. Basic Information Original Title: Warlock Ransomware Attackers Hit Water and Telecom Operators Sources: Symantec and Carbon Black Published: October 1, 2026 Updated: None Severity: Critical…

  • Warlock ransomware deployed from compromised SharePoint servers
  • Attackers used DLL sideloading and remote access tools
  • SYSVOL scripts directory used to distribute ransomware to 33+ machines

More from Friday 2 October →