
GitLab CVE-2026-85706: Critical Path Traversal Vulnerability Exploited Within 24 Hours
Breaking NewsHackingSecurityCVE-2026-85706GitLabPath TraversalZero AuthenticationCritical VulnerabilityExploit
GitLab disclosed CVE-2026-85706 on September 10, 2026, a path traversal vulnerability in its repository commits API with a CVSS score of 10.0. The vulnerability was under active exploitation within 24 hours of disclosure. CVE-2026-85706 allows attackers to access files they should not see through a crafted request, requiring no authentication and only one HTTP request for full file read capability.