LOWVulnerability
CVE-2026-85706
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
Properties
- product
- Community Edition and Enterprise Edition
- vulnerabilityName
- GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
- cve_id
- CVE-2026-85706
- signal_observed_at
- 2026-09-11T21:54:02+00:00
- dueDate
- 2026-09-14
- vendorProject
- GitLab
- requiredAction
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
- dateAdded
- 2026-09-11
Related Entities (1)
KNOWN_EXPLOITED (1)
→[Source]CISA KEV
Explore deeper with Ninja Signal's threat intelligence graph