Maximum Severity GitLab Flaw Puts Supply Chains at Risk
At a glance
- Severity
- CriticalCVSS 10.0
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-85706
- Vendors and products
- GitLab
- Reported by
- 1 outlet
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Vulnerabilities referenced
- CVE-2026-8570610.0Critical
GitLab Community Edition and Enterprise Edition
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
Used in attacksAdded to CISA's list 2026-09-11
Full record →
Coverage
One outlet has carried this so far.
2026-09-14 20:19 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News · 2026-09-16
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News · 2026-09-16 · exploited