GitLab recently disclosed a critical vulnerability impacting GitLab Community Edition and Enterprise Edition, and just one day later, cyber security analysts were observing malicious probing of the path traversal bug.
CVE-2026-85706 has a CVSS score of 10 and could allow an unauthenticated attacker to read “arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API”.
This impacts all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2, GitLab said in a 10 September critical patch release.
CVE-2026-85706 was one of several issues addressed in the patch release, but it’s this one that’s got researchers worried.
“This is the second instance of a critical-severity GitLab vulnerability in recent weeks, following the previous GraphQL code injection (CVE-2026-19478) that was almost immediately actively exploited,” Jake Knott, head of threat intelligence at watchTowr, told Cyber Daily.
“The appeal to attackers of GitLab is obvious, as unauthorised access allows an attacker to gain access to source code, CI/CD secrets, credentials, and the ability to inject code into build pipelines, gaining access or poisoning anything downstream of it, which, as we’ve seen throughout this year, has been a favourite of attackers.”
And with analysts already seeing probing, full exploitation is only a matter of time.
“Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away,” watchTowr said in a LinkedIn post soon after it first observed the malicious activity.
“Organisations with public-facing self-hosted GitLab instances should patch as soon as possible or remove public access.”
According to Knott, one of the reasons this vulnerability is so dangerous is that there really is only one requirement for exploitation: at least one public project must exist.
“An attacker can target common sensitive files, such as log files, or GitLab-specific configuration files that contain credentials, keys, and tokens. watchTowr has fully reproduced this vulnerability internally, and has already observed in-the-wild probes for the vulnerability since 06:00 UTC on September 11th, proving that it has already been reverse-engineered,” Knott said.
“Organisations running self-managed GitLab instances exposed to the internet should patch immediately where possible, or restrict public access. Based on the history, the transition of this vulnerability to indiscriminate mass exploitation is likely not far away, and defenders have limited time to act.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.