Interestana
Home/News/GitLab Patches Critical CVSS 10 File-Read Vulnerability
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

GitLab Patches Critical CVSS 10 File-Read Vulnerability

GitLab Patches Critical CVSS 10 File-Read Vulnerability

GitLab has issued patches for several security vulnerabilities, most notably a critical flaw with a CVSS score of 10.0, which has already attracted in-the-wild exploitation attempts shortly after its public disclosure. This maximum-severity vulnerability, identified as CVE-2026-85706, is a path traversal issue affecting the repository commits API. It permits unauthenticated users to read any file on the GitLab server. The potential impact of this vulnerability is significant, as it could expose sensitive configuration files, source code, or other critical data stored on the affected GitLab instance. The company has confirmed that the vulnerability was addressed in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 17.3.4, 17.2.6, and 17.1.10. Users are strongly urged to update to these patched versions as soon as possible to mitigate the risk of exploitation. The disclosure of CVE-2026-85706 highlights the ongoing challenges in securing complex software platforms like GitLab, which are widely used for code hosting and collaboration by organizations globally. The rapid exploitation following disclosure underscores the importance of prompt patching and robust security monitoring for such systems. Beyond the critical CVE-2026-85706, GitLab also addressed other vulnerabilities in its latest security release. These include CVE-2024-29792, a medium-severity flaw related to container registry image deletion, and CVE-2024-31161, another medium-severity issue concerning the project import functionality. Additionally, CVE-2024-31162, a low-severity vulnerability, was patched within the security dashboard. The company's commitment to addressing these issues reflects its ongoing efforts to maintain the security posture of its platform. GitLab, a web-based DevOps lifecycle tool, provides a comprehensive suite of features for software development, including source code management, continuous integration and continuous delivery (CI/CD), issue tracking, and more. Its widespread adoption across various industries makes the security of its platform a paramount concern for businesses and developers alike. The company's proactive approach to releasing patches and informing its user base about critical vulnerabilities is a crucial aspect of its security strategy. The swift identification and remediation of such high-severity flaws are essential to prevent potential data breaches and maintain the integrity of development workflows. The fact that CVE-2026-85706 was exploited in the wild so quickly after disclosure serves as a stark reminder of the persistent threat landscape and the need for continuous vigilance in cybersecurity.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next