Maximum Severity GitLab Flaw Puts Supply Chains at Risk

Used in attacksCriticalCVSS 10.0Dark Reading · Rob Wright·

At a glance

Severity
CriticalCVSS 10.0
Used in attacks
Yes, 1 of 1 flaw named
Flaws named
CVE-2026-85706
Vendors and products
GitLab
Reported by
1 outlet

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

Vulnerabilities referenced

  • CVE-2026-8570610.0Critical

    GitLab Community Edition and Enterprise Edition

    GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

    Used in attacks

    Added to CISA's list 2026-09-11

    Full record →

Coverage

One outlet has carried this so far.

  1. Dark ReadingEstablished SourceFirst reported

    2026-09-14 20:19 UTC

Related stories