Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you — not vendor summaries written a week late.

Rapid Reaction: GitLab Path Traversal Vulnerability (CVE-2026-85706)

On September 10, 2026, GitLab released versions 19.3.2, 19.2.6, and 19.1.8 for GitLab Community Edition and Enterprise Edition. The release addresses a critical path traversal vulnerability tracked as CVE-2026-85706, affecting the repository commits API. GitLab assigned this issue a CVSS score of 10.0, and watchTowr assesses with a high confidence that this vulnerability will rapidly…

On September 10, 2026, GitLab released versions 19.3.2, 19.2.6, and 19.1.8 for GitLab Community Edition and Enterprise Edition. The release addresses a critical path traversal vulnerability tracked as CVE-2026-85706, affecting the repository commits API. GitLab assigned this issue a CVSS score of 10.0, and watchTowr assesses with a high confidence that this vulnerability will rapidly transition to indiscriminate, in-the-wild exploitation given the low complexity of exploitation.

watchTowr reviewed the technical details published by GitLab, reproduced the vulnerability, and validated exposure across client environments running self-managed GitLab instances. watchTowr Intel is already seeing behavioral probes for this vulnerability against Attacker Eye, our global honeypot network, meaning attackers have already successfully reverse engineered and reproduced the vulnerability and the countdown to indiscriminate, in-the-wild exploitation is on.

Organizations running self-hosted versions of GitLab should apply patches as a priority. If you need urgent help assessing exposure, contact us here.

What Is GitLab?

GitLab is a widely deployed DevOps platform used for source code management, CI/CD pipelines, and application security workflows. It is used by enterprises of all sizes to store source code, manage releases, and run build and deployment pipelines. Because GitLab instances often hold sensitive source code, credentials, and CI/CD configuration data, any vulnerability that allows unauthorized file access carries significant risk to enterprise environments.

What Is the GitLab Path Traversal Vulnerability?

The GitLab Path Traversal Vulnerability (CVE-2026-85706) is a path traversal issue in the repository commits API within GitLab CE and EE. According to GitLab, under certain conditions an unauthenticated user could read arbitrary files from the GitLab server. The root cause is improper path confinement combined with missing authentication enforcement in the affected API endpoint.

In practical terms, an attacker with no credentials could send a request to the commits API and have the application return the contents of files it should never have exposed, potentially including configuration files, secrets, or other sensitive server-side data. The lack of any authentication requirement, combined with the low attack complexity, is reflected in the CVSS 10.0 score assigned to this issue.

What Is Affected

Product NameAffected Versions
GitLab CE/EEAll versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2

What Should You Do

Organizations with public-facing self-hosted GitLab instances should patch as soon as possible or remove public access.

Defenders should also hunt through log files for HTTP POST requests to “/api/v4/projects/{id}/repository/commits/” URIs containing “file.path” parameters to identify potential exploitation attempts.

  1. Identify every self-managed GitLab instance in your environment and confirm the exact version in use.
  2. Prioritize patching any instance running an affected version, given the unauthenticated attack path and CVSS 10.0 rating.
  3. Review recent access logs on the repository commits API for unusual or unauthenticated requests that may indicate probing or exploitation attempts.
  4. Confirm that GitLab.com and GitLab Dedicated deployments require no further action, and document this for audit purposes.
  5. Upgrade affected installations to the patched versions listed below as soon as possible.
Product NamePatched Version(s)
GitLab CE/EE19.1.8, 19.2.6, 19.3.2

How watchTowr Helps Respond to the GitLab Path Traversal Vulnerability

The watchTowr Platform delivers Preemptive Exposure Management, identifying, validating, and mitigating external exposure across enterprise environments.

  • watchTowr Instinct: assessed CVE-2026-85706 as high-likelihood for in-the-wild exploitation in real-time as the vulnerability was disclosed.
  • Project Red: autonomously reproduced the threat, CVE-2026-85706.
  • Adversary Sight engine: identified GitLab instances across client environments and assessed exposure.
  • Attacker Eye: our global honeypot network, is monitoring for in-the-wild exploitation activity as it emerges.
  • Rapid Reaction: was leveraged across the watchTowr client base to identify exposure to this vulnerability and give teams the time they need to act.
  • Active Defense: released targeted network-level mitigations to clients, enabling immediate risk reduction while permanent fixes are applied.
 Request a demo to see how Rapid Reaction protects your environment from emerging threats like this GitLab Critical Path Traversal Vulnerability (CVE-2026-85706).

If you are a watchTowr client

Rapid Reaction has already run against your validated attack surface. Affected assets are flagged in your console with confirmed exploitability, and Active Defense mitigation rules were made available for your edge controls within the hour. You do not need to open a ticket.

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

On this page

Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.