GitLab CE/EE Repository Commits API Path Traversal Vulnerability
CVE-2026-85706 is a critical path traversal vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerability exists in the repository commits API and, under certain conditions, allows an unauthenticated attacker to read arbitrary files from an affected GitLab server due to improper path confinement and missing authentication enforcement. GitLab assigned the vulnerability a CVSS 3.1 score of 10.0 (Critical) and strongly recommends that affected self-managed installations be upgraded immediately.
Technical Details
CVE-2026-85706 affects GitLab’s repository commits API. GitLab describes the underlying issue as a combination of improper path confinement and missing authentication enforcement. Under certain conditions, an unauthenticated attacker can exploit the flaw to read arbitrary files from the GitLab server.
Successful exploitation can expose files accessible to the GitLab server process. Depending on the deployment and file permissions, this may include sensitive configuration information, credentials, secrets, tokens, SSH keys, database credentials, or other server-side data.
The vulnerability requires no authentication or user interaction and is remotely exploitable with low attack complexity. GitLab assigned the following CVSS 3.1 vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
The resulting score is 10.0 (Critical).
Stop Guessing, Start Proving

NodeZero® Proactive Security Platform — Rapid Response
A NodeZero Rapid Response test has been developed to safely validate whether this vulnerability can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
- Run the Rapid Response test: Launch from the NodeZero platform to determine whether exploitation is possible.
- Patch immediately: Upgrade affected self-managed GitLab installations to a fixed version.
- Re-run the test: Confirm the vulnerability is no longer exploitable after remediation.
Affected Versions & Patch
Affected
GitLab CE and EE:
- 18.7 through 19.1.7
- 19.2.0 through 19.2.5
- 19.3.0 through 19.3.1
GitLab describes these ranges as all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.
Fixed
Upgrade to one of the patched releases:
- 19.1.8
- 19.2.6
- 19.3.2
GitLab strongly recommends that all affected self-managed installations upgrade immediately. GitLab.com is already running a patched version, and GitLab Dedicated customers do not need to take action.
Mitigations
There is no vendor-provided workaround that should be treated as an alternative to patching. Organizations should prioritize upgrading affected self-managed installations.
Where immediate patching is not possible, restricting network access to vulnerable GitLab instances can reduce exposure, but it should be treated as a temporary risk-reduction measure rather than a fix.
Because successful exploitation can expose sensitive server-side files, organizations with vulnerable internet-accessible instances should also evaluate whether credentials or secrets accessible to the GitLab process require rotation.
Timeline
- September 10, 2026: GitLab released versions 19.3.2, 19.2.6, and 19.1.8, addressing CVE-2026-85706, and urged self-managed customers to upgrade immediately.
- September 11, 2026: Public reporting highlighted CVE-2026-85706 as a maximum-severity unauthenticated path traversal vulnerability.
- September 11, 2026: Horizon3 released a NodeZero Rapid Response test for CVE-2026-85706.
