vulns.comcp

← CVE intelligence

CVE-2026-85706 - GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

Severity
critical
Product
GitLab Community Edition and Enterprise Edition
Published
2026-09-11
EPSS
0.914
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.