Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: gitlab (3 articles)Clear

Critical GitLab flaw lets one request read any file from self-hosted servers

CISA warned that attackers are exploiting a critical flaw in self-managed GitLab servers, adding it to its exploited-vulnerabilities catalog with a forensic-triage requirement. Tracked as CVE-2026-85706 and scored 10.0, it is a path-traversal bug in GitLab's repository commits API caused by improper path confinement and missing authentication, letting an unauthenticated attacker read any file on the server with a single crafted request. Exposed files can include SSH keys, database credentials, deploy tokens, CI/CD variables, and source code. GitLab patched it on September 10, and researchers observed in-the-wild probing within about a day. GitLab.com is unaffected; the risk is concentrated on the many self-managed instances organizations run.

Check
Upgrade self-managed GitLab to 19.1.8, 19.2.6, 19.3.2, or later immediately, then rotate secrets the server could expose, including access tokens, deploy tokens, CI/CD variables, SSH keys, and cloud credentials.
Affected
Organizations running self-managed GitLab CE or EE from 18.7 up to the patched releases (CVE-2026-85706); an unauthenticated attacker can read arbitrary files, including secrets and source, in one request.
Fix
Patch now, rotate all potentially exposed secrets, review commits-API and web-server logs for unauthenticated requests with traversal patterns and unusual file access, and treat exposed unpatched instances as possibly already breached.

Critical GitLab flaw lets unauthenticated attackers delete public projects and data

GitLab shipped an out-of-band critical patch for a flaw that lets an unauthenticated attacker remotely modify or delete public projects and user data through a GraphQL directive. Tracked as CVE-2026-19478 and scored 9.4, it affects self-managed Community and Enterprise installations; GitLab.com and Dedicated are already fixed. The company released it outside its normal twice-monthly schedule, and the fixed versions are 19.2.4, 19.1.6, 19.0.8, and 18.11.11, with the 18.2 through 18.10 branches left in the affected range and needing an upgrade. A second, lower-severity GraphQL flaw involving cross-site request forgery was fixed in the same release. GitLab reports no known exploitation yet.

Check
Upgrade self-managed GitLab to a fixed release immediately, and if you run a version between 18.2 and 18.10, plan an upgrade since those branches did not receive a backported fix.
Affected
Organizations running self-managed GitLab Community or Enterprise Edition (CVE-2026-19478); an unauthenticated attacker can remotely modify or delete public projects and user data through a GraphQL directive.
Fix
Apply the out-of-band patch now, prioritize internet-reachable instances, review logs for unexpected GraphQL activity and project or user changes, and restore any affected projects from backups if tampering is found.

Public exploit runs commands as git on unpatched self-managed GitLab servers

A researcher at depthfirst published a working exploit on July 24 for a GitLab flaw patched on June 10, running commands as the git user on any self-managed 18.11.3 server that has not updated. Any authenticated user who can push to a project can trigger it: the attacker commits a crafted Jupyter notebook and opens its commit diff to leak a heap pointer, repeats until an automated probe locates libraries in memory, then fires the payload with two more notebooks. No administrator rights, runner access, or victim interaction are needed. The bug sits in the notebook renderer, which passes repository-controlled data to a parser inside a long-lived worker.

Check
Move self-managed GitLab to a supported release containing the June fix, and for Helm or Operator deployments verify the GitLab version inside the Webservice image rather than only the chart version.
Affected
Self-managed GitLab servers on 18.11.3 or other unpatched builds; any authenticated user able to push a project can run commands as the git service account, with public exploit code now available.
Fix
Upgrade to a fixed release, since no workaround is offered, and note GitLab did not classify the fix as a security issue, so track upstream library bumps rather than security advisories alone.