{
  "id": 11721829,
  "title": "GitLab Vulnerability Under Active Exploitation Enables Unauthenticated Data Exfiltration",
  "url": "https://urgent.news/2026/10/03/gitlab-vulnerability-under-active-exploitation-enables",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T16:00:00.000Z",
  "source": {
    "name": "InfoQ",
    "slug": "infoq",
    "url": "https://www.infoq.com/news/2026/10/gitlab-critical-vulnerabilities/"
  },
  "original_language": "en",
  "account": "GitLab's CVE-2026-85706 vulnerability has transitioned from a theoretical threat to confirmed exploitation, enabling unauthenticated remote attackers to read arbitrary files from self-managed GitLab instances. Affecting versions 18.7 to 19.3.1, this critical vulnerability, rated 10.0 on the CVSS scale, poses a significant risk of secret theft and CI/CD pipeline compromise. The bug arises from improper path confinement and insufficient authentication enforcement in the repository commits API. Initial disclosure prompted immediate patch deployment by GitLab on September 11, but attackers began probing shortly after, and the U.S. Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities Catalog. Security experts urge rotating compromised credentials and checking for potential exploitation in log files by targeting specific HTTP POST requests. While patching stops new file reads, it doesn't revoke stolen deploy tokens, CI variables, or SSH keys. Cybersecurity leaders emphasize the minimal requirements for exploitation, including at least one public project, and stress the importance of adopting additional safety measures such as restricting internet exposure and rotating affected secrets. GitLab has backported the fix to end-of-life versions 19.0.9 and 18.11.12 of their Community Edition and Enterprise Edition, respectively.",
  "summary": "CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab. By Sergio De Simone",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}