## Overview
CISA has added CVE-2026-85706 to its Known Exploited Vulnerabilities (KEV) list. This vulnerability affects GitLab Community Edition and Enterprise Edition. It impacts all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The addition to the KEV list indicates a federal deadline for remediation.
## Technical Details
CVE-2026-85706 is a path traversal vulnerability. It allows an unauthenticated user to read arbitrary files from the GitLab server. This occurs due to improper path confinement and missing authentication enforcement in the repository commits API. Attackers can exploit this weakness to access sensitive data stored on the server.
## Impact
The vulnerability poses a critical risk, rated with a CVSS score of 10.0. Successful exploitation could lead to unauthorized access to sensitive files, potentially compromising user data and server integrity. Organizations using affected GitLab versions must act swiftly to mitigate risks.
## Mitigation
GitLab has released patches to address this vulnerability. Users must upgrade to the following versions to secure their systems: 19.1.8 or later, 19.2.6 or later, and 19.3.2 or later. It is crucial for organizations to apply these updates immediately to prevent exploitation.
CSURFACE Threat Sensor