{
  "id": 11317291,
  "title": "GitLab CVE-2026-85706: Why an Arbitrary File Read on a DevSecOps Platform Is a Credential Incident",
  "url": "https://urgent.news/2026/10/02/gitlab-cve-2026-85706-why-an-arbitrary-file-read-on-a-devsecops",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T00:40:23.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bianliang/gitlab-cve-2026-85706-why-an-arbitrary-file-read-on-a-devsecops-platform-is-a-credential-incident-3g2b"
  },
  "original_language": "en",
  "account": null,
  "summary": "GitLab has released updates to address CVE-2026-85706, an arbitrary file read vulnerability on their DevSecOps platform. This issue arises due to improper path restriction and missing authentication in the repository commits API, allowing unauthenticated attackers to read arbitrary files from the server. The CVSS 3.1 base score for this vulnerability is 10.0, and CISA has added it to its Known Exploited Vulnerabilities catalog, confirming real-world exploitation. The true risk of this vulnerability lies in the fact that the files GitLab processes can access often include sensitive credentials rather than just content. By exploiting this vulnerability, an attacker can obtain sensitive information such as instance secrets, database and cache passwords, Runner and container registry credentials, object storage keys, OAuth and webhook secrets, and deployment tokens or private keys used by automation. While patching the vulnerability closes the original door, it does not invalidate the duplicated keys that attackers may have already used. GitLab has released updates for self-managed Community Edition and Enterprise Edition across three branches, while GitLab.com and Dedicated customers do not require updates as they were patched by the vendor. Detecting exploitation in logs can be achieved by searching for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ with a file.path parameter.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}