GitLab has released security updates to address multiple vulnerabilities in its platform, including a maximum severity flaw that has already attracted in the wild probing activity shortly after public disclosure. The critical vulnerability, tracked as CVE 2026 85706 with a CVSS score of 10.0, affects GitLab repository commits API functionality and could allow unauthenticated users to access arbitrary files stored on vulnerable GitLab servers under certain conditions. GitLab said the issue was caused by improper path confinement and missing authentication enforcement within the repository commits API. The company has urged organizations operating affected self managed GitLab instances, especially those exposed to the internet, to apply the available security patches as soon as possible or restrict public access where exposure is not required.
The vulnerability impacts several versions of GitLab Community Edition (CE) and Enterprise Edition (EE), including all versions from 18.7 before 19.1.8, versions from 19.2 before 19.2.6, and versions from 19.3 before 19.3.2. Security researchers at exposure management company watchTowr reported that active scanning attempts targeting the vulnerability began shortly after disclosure. According to the company, exploitation activity was observed from 06:00 UTC on September 11, 2026. Researchers said the flaw could allow external attackers to access sensitive files, including log files and GitLab specific configuration files that may contain credentials, secrets, and other confidential information. Jake Knott, head of threat intelligence at watchTowr, said the vulnerability represents another critical GitLab security issue following a previous GraphQL code injection vulnerability, CVE 2026 19478, which also faced exploitation activity shortly after being identified.
GitLab repositories often contain valuable development assets, making unauthorized access a significant concern for organizations using the platform. According to watchTowr, attackers gaining access to GitLab environments could potentially obtain source code, CI/CD pipeline secrets, credentials, and other information that could enable further compromise. The researcher noted that exploitation of CVE 2026 85706 requires only one condition, the presence of at least one publicly available project. Security teams have been advised to review their GitLab deployments, monitor activity involving repository commit API requests, and investigate unusual requests containing specific file path parameters. Organizations can also review HTTP POST requests targeting /api/v4/projects/{id}/repository/commits/ URLs that include file.Path parameters as part of efforts to identify possible exploitation attempts.
Alongside the critical file read vulnerability, GitLab also patched another serious security issue affecting Enterprise Edition. The flaw, tracked as CVE 2026 87719 with a CVSS score of 9.9, is an insecure deserialization vulnerability that could result in information exposure. GitLab explained that an authenticated user with access to Duo Chat could potentially obtain Advanced Search instance configurations and sensitive credentials by submitting a specially crafted GraphQL subscription argument. The issue involved bypassing serialization protections and performing server object lookups that could reveal restricted information. With active probing already observed against the CVSS 10 vulnerability, security teams are being encouraged to prioritize updates and evaluate internet facing GitLab deployments. Researchers warned that based on previous vulnerability trends, widespread exploitation could follow quickly, leaving organizations with limited time to strengthen defenses and prevent unauthorized access to development environments and sensitive business data.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





