GitLab Vulnerability Exploited One Day After Disclosure

https://www.securityweek.com/wp-content/uploads/2026/06/GitLab.jpeg

Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns.

Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that can allow unauthenticated users to read arbitrary files from the GitLab server.

All Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.

On Friday, one day after GitLab announced patches for the security weakness, WatchTowr observed the first in-the-wild exploitation attempts targeting it.

“WatchTowr Intel is already observing in-the-wild probes for the latest critical GitLab Path Traversal vulnerability, CVE-2026-85706, which allows attackers to read arbitrary files in a single HTTP request,” the company said.

According to WatchTowr, mass exploitation of the vulnerability is likely to follow shortly.

Advertisement. Scroll to continue reading.

“Defenders should hunt through log...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more