GitLab’s critical flaw is already drawing internet-wide probes

MediumCyberScoop · Greg Otto·
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws.

The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. GitLab said its own hosted service already runs the fixed code, and that customers of its single-tenant Dedicated offering are not impacted.

The more serious of the two flaws, tracked as CVE-2026-85706, sits in the interface that handles repository commits. GitLab said that under certain conditions an attacker could read any file on the server, because the code failed to confine file paths properly and did not enforce authentication. An attacker does not need an account nor credentials to take advantage of the flaw.

The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches. GitLab assigned it a CVSS score of 10.0, the top of the scale used across the industry.

The second flaw, CVE-2026-87719, affects only GitLab’s Enterprise Edition. The company says a logged-in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced Search feature, which would return the settings and passwords being held. It affects releases from 18.3 onward and carries a CVSS score of 9.9. 

WatchTowr Labs wrote in a LinkedIn post Friday that it was already watching probes against the path traversal flaw, which it said an attacker can trigger in one HTTP request. The firm said organizations running self-hosted GitLab servers reachable from the open internet face the greatest risk, and pointed defenders toward their logs, suggesting they look for POST requests to addresses under /api/v4/projects/{id}/repository/commits/ that carry a file.path parameter. 

Drawing on earlier GitLab flaws, the firm said broad, untargeted attacks tend to follow soon after a patch appears.

“Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away,” the post read. 

The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) list on Friday afternoon. 

You can find more information about the vulnerabilities on GitLab’s website

Update: Sept. 11, 2026; 4:30 p.m.: This story has been updated to reflect the vulnerability being added to CISA’s KEV list.

Latest Podcasts

Government

Technology

Threats

Policy

Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Greg Otto.

Read at cyberscoop.comEstablished Source

At a glance

Severity
Mediumfrom category and source signals; no CVSS referenced
Exploitation
No vulnerabilities referenced
Vulnerabilities
None referenced
Vendors & products
GitLab
Threat actors & malware
None named
Industries
Not industry-specific
Coverage
1 outlet· first seen 2026-09-11 18:41 UTC
Priority
41/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.

Coverage

One outlet has carried this so far.

  1. CyberScoopEstablished SourceFirst reported

    2026-09-11 18:41 UTC

Related stories