GitLab vulnerability exploited one day after disclosure

GitLab vulnerability exploited one day after disclosure

Threat actors have begun exploiting a newly patched vulnerability in GitLab a day after it was made public, attack surface management company WatchTowr warns.

The security flaw, tracked as CVE-2026-85706 (CVSS score 10/10), is described as a path traversal issue that could allow unauthenticated users to read arbitrary files from the GitLab server.

All Community Edition (CE) and Enterprise Edition (EE) versions of 18.7 before 19.1.8, 19.2 before 19.2.6 and 19.3 before 19.3.2 are affected.

On Friday, a day after GitLab’s announcement patches WatchTowr observed the first open attempts to exploit the vulnerability.

“WatchTowr Intel is already monitoring ongoing investigations into the latest critical GitLab Path Traversal vulnerability CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,” the company said said.

“This is the second case of a critical GitLab vulnerability in recent weeks, following the previous GraphQL code injection (CVE-2026-19478), which was actively exploited almost immediately,” said Jake Knott, head of threat analysis at WatchTowr.

Advertising. Scroll to continue reading.

According to WatchTowr, mass exploitation of the vulnerability is likely to occur soon.

“Defenders should search log files for HTTP POST requests to ‘/api/v4/projects/{id}/repository/commits/’ URIs that contain ‘file.path’ parameters to identify potential exploitation attempts,” the company noted.

Self-hosted GitLab instances should be updated as soon as possible as the new patches address 17 additional vulnerabilities, including another critical severity bug.

The critical flaw, tracked as CVE-2026-87719 (CVSS score of 9.9/10), is an insecure deserialization issue in the GraphQL subscription serializer that could allow attackers to access “advanced search instance configurations and sensitive credentials.”

GitLab CE/EE versions 19.1.8, 19.2.6, and 19.3.2 also address six high-severity security flaws that could allow attackers to remotely execute code, access protected CI/CD variables, launch XSS attacks, and cause denial of service conditions.

“The attractiveness of GitLab to attackers is clear, as unauthorized access allows an attacker to gain access to source code, CI/CD secrets, credentials, and the ability to inject code into build pipelines and gain access to or poison anything downstream, which, as we’ve seen all year, has been popular with attackers,” Knott added.

Related: In other news: InjectEave attack, SIM swapper convicted, Glasswing findings review

Related: Check Point fixes critical VPN vulnerabilities

Related: PaperCut errors are exploited in AI-powered attacks

Related: Critical NetScaler vulnerability is exploited in attacks

Leave a Reply

Your email address will not be published. Required fields are marked *