The Cybersecurity and Infrastructure Security Agency (CISA) has added GitLab's CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) catalog. This critical flaw is a path traversal vulnerability that allows attackers to access sensitive data, such as login credentials or confidential files, without needing to authenticate. The vulnerability exists in GitLab's repository commits API, which is a tool used to track changes in code repositories. GitLab has released patches for both its Community Edition (CE) and Enterprise Edition (EE), with updated versions including 19.3.2, 19.2.6, and 19.1.
The vulnerability arises from missing authentication checks and inadequate restrictions on file paths within the API. According to a report by cybersecurity researchers at watchTowr, this flaw is already being actively exploited by attackers. The report noted that attackers can read any file on a system with a single HTTP request. To detect such attacks, security teams are advised to monitor log files for suspicious HTTP POST requests directed at specific URLs that include 'file.path' parameters.
CISA has given government agencies a three-day window to apply the necessary patches to protect their systems from exploitation. GitLab is a widely used platform that supports DevSecOps, a practice that integrates security into the software development lifecycle. It is used by over 50 million registered users, including approximately half of the Fortune 100 companies, making it a critical tool for organizations across various industries.
The inclusion of this vulnerability in CISA’s KEV catalog underscores the severity of the flaw and the urgency for organizations to address it. As a result, companies using GitLab are strongly encouraged to update their systems promptly to prevent potential breaches and protect sensitive data from being exposed.
CISA Adds Critical GitLab Vulnerability to KEV Catalog Amid Active Exploitation Reports
AI-rewritten from original reportingHow it works
cisagitlabcve-2026-85706path-traversaldevsecopssecurity-patch



