Skip to content
skopnix
actively exploited · CISA KEV

CVE-2026-85706

NVD CRITICAL 10 · published 2026-09-12 · 1 on the wire

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Exploited in the wild

Yes

CISA added it 2026-09-11. An observation, not a forecast.

EPSS · 30-day forecast

12%

Chance of exploitation in the next 30 days, 96th percentile of all CVEs. A forecast; KEV outranks it.

CVSS · NVD

10.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Internet exposure

No exposure census on this CVE's dispatches.

On the wire1
References
Early access

Watch this one?

Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.

bot-protected