Report
GitLab patches maximum-severity path traversal flaw, urges self-managed users to upgrade
GitLab released fixes for a maximum-severity path traversal vulnerability, CVE-2026-85706, and a second critical flaw, CVE-2026-87719. The company urged self-managed installations to upgrade immediately, while a security firm reported early scanning for exposed servers.
GitLab has released patches for a maximum-severity path traversal vulnerability tracked as CVE-2026-85706, and urged users to update their servers immediately. The flaw stems from improper path confinement and missing authentication enforcement in the repository commits API. According to GitLab, unauthenticated attackers can exploit it "under certain conditions" to read arbitrary data, such as credentials, secrets, and sensitive information, from vulnerable servers. The company has not flagged the flaw as exploited in the wild.
Who is exposed? Self-managed GitLab installations that have not applied the fixes. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. The fixed versions are GitLab Community Edition (CE) and Enterprise Edition (EE) 19.3.2, 19.2.6, and 19.1. GitLab strongly recommends that all self-managed installations upgrade to one of these versions immediately.
The protective step is straightforward: upgrade to a patched version. Additionally, watchTowr reported that attackers have begun searching for internet-exposed GitLab servers unpatched against CVE-2026-85706. The firm warned that indiscriminate exploitation is likely not far away, based on recent GitLab vulnerabilities. Defenders can hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts.
GitLab also patched a second critical vulnerability, CVE-2026-87719, which affects GitLab EE and stems from an insecure deserialization weakness in the GraphQL subscription serializer. It allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations. The two flaws were fixed in the same release. Historically, GitLab has dealt with similar path traversal issues, including a maximum-severity flaw in May 2023 (CVE-2023-2825). Since November 2021, CISA has flagged four GitLab vulnerabilities as exploited in attacks.
Our reading
Our reading is that self-managed GitLab administrators should treat this as an urgent patch-or-be-scanned situation, given watchTowr's early probes and GitLab's history of path traversal flaws being targeted.
What to do or watch
Self-managed GitLab administrators should upgrade to the patched releases (19.3.2, 19.2.6, or 19.1) and hunt their logs for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters, which watchTowr says can indicate exploitation attempts. The unresolved question is whether CVE-2026-85706 will follow the pattern of previous GitLab flaws into indiscriminate exploitation; GitLab has not yet flagged it as exploited in the wild, while watchTowr reports…
Source details and supporting facts
Each line is stated by the page named above it.
Stated by BleepingComputer
- GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.
- The flaw stems from improper path confinement and missing authentication enforcement in the repository commits API.
- Unauthenticated attackers can exploit CVE-2026-85706 "under certain conditions" to read arbitrary data (e.g., credentials, secrets, and sensitive information) from vulnerable servers.
- GitLab fixed the two security issues in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1.
- GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action.
- watchTowr reported that attackers have already begun searching for Internet-exposed GitLab servers unpatched against CVE-2026-85706.
- Defenders should also hunt through log files for HTTP POST requests to '/api/v4/projects/{id}/repository/commits/' URIs containing 'file.path' parameters to identify potential exploitation attempts.
- GitLab patched a second critical vulnerability tracked as CVE-2026-87719 that stems from an insecure deserialization weakness in the GraphQL subscription serializer.
- CVE-2026-87719 affects GitLab EE and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
Sources
- BleepingComputerText stored 12 September 2026
How this story was checked. Written from the 1 page listed above, stored 12 September 2026; claims checked against that stored text on 14 September 2026.
What that means
- 9 of 9 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief