CVE-2026-85706

gitlab: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2026-85706)

Affected

  • gitlab/gitlab between 18.7.0..19.1.8
  • gitlab/gitlab between 18.7.0..19.1.8
  • gitlab/gitlab between 19.2.0..19.2.6
  • gitlab/gitlab between 19.2.0..19.2.6
  • gitlab/gitlab between 19.3.0..19.3.2
  • gitlab/gitlab between 19.3.0..19.3.2

Response & Mitigation

Why act now?

Prioritisation rationale

This vulnerability allows an unauthenticated attacker to read arbitrary files from the GitLab server — including CI/CD secrets, SSH keys, configuration files, and source code — with zero authentication required. For organisations using GitLab as a central DevSecOps platform, successful exploitation can directly enable supply-chain compromise, making the blast radius far larger than a typical server-side file-read flaw. NIS2-scoped organisations must demonstrate adequate technical controls under Article 21; a publicly reachable, unpatched GitLab instance represents a material compliance gap in addition to the operational risk. The CISA KEV listing without a known ransomware-campaign flag is consistent with targeted reconnaissance or credential-harvesting activity — however, secrets exfiltration is a well-established precursor to broader intrusions, so patch priority should be treated as critical regardless of the ransomware flag.

Runbook · Step 1

Immediate response (0-24 h)

  • Apply the vendor patch now: Upgrade GitLab CE/EE to 19.3.2, 19.2.6, or 19.1.8 depending on your active release branch. After the package update, run gitlab-ctl reconfigure && gitlab-ctl restart — no full host reboot required.
  • Block the vulnerable API endpoint externally: At your WAF or reverse proxy, immediately deny inbound requests to /api/v4/projects/:id/repository/commits from untrusted networks until the patch is confirmed deployed and verified.
  • Enforce authentication at the application level: In Admin Area → Settings → General → Visibility and access controls, set restricted visibility levels and disable public project access to eliminate the unauthenticated attack surface.
  • Preserve access logs: Archive the last 30 days of Nginx/Workhorse access logs to immutable storage (WORM or log-SIEM ingestion) before any rotation occurs — these are your primary forensic evidence for determining whether exploitation has already taken place.
  • Rotate all secrets stored in GitLab: Treat all CI/CD variables, deploy keys, personal access tokens, and any secrets committed to repositories as potentially exfiltrated. Rotate immediately, prioritising credentials with production or cloud-provider access.

Runbook · Step 2

Mitigation layers

  • Network segmentation: Place GitLab instances not requiring public internet exposure behind a VPN or Zero Trust gateway. Restrict TCP 443 and TCP 22 to authorised source IP ranges at the perimeter firewall.
  • WAF path-traversal rule: Block requests containing URL-encoded or double-encoded traversal sequences (%2F..%2F, %252F, ..%2F, ....//). ModSecurity example: SecRule REQUEST_URI "@rx (?:%2e%2e|%252e%252e|\.\.)[%2f/\\]" "id:9001,phase:1,deny,log,msg:'Path Traversal CVE-2026-85706'".
  • IPS signature (Suricata): alert http any any -> $GITLAB_SERVERS any (msg:"CVE-2026-85706 Path Traversal"; content:"/api/v4/projects/"; content:"commits"; pcre:"/(%2e%2e|\.\.)[%2f\/]/i"; sid:2026857060; rev:1;).
  • Least-privilege for service accounts: Scope CI/CD runner tokens and deploy tokens to individual projects; disable group-level tokens unless operationally required. Revoke any tokens with owner-level permissions that are not actively needed.
  • Host-level hardening: Ensure the git process user cannot read files outside the GitLab data path. Activate AppArmor or SELinux profiles for gitlab-workhorse and gitaly with deny-by-default posture, explicitly blocking reads of /etc/shadow, SSH host keys, and other sensitive system files.

Runbook · Step 3

Detection rules

  • Web server access log (Nginx/Workhorse) — SPL: index=weblogs sourcetype=nginx_access uri_path="/api/v4/projects/*/repository/commits" (uri_path="*../*" OR uri_path="*%2e%2e*") status!=401 status!=403 | stats count by src_ip, uri_path
  • Sigma rule shape (HTTP anomaly): title: CVE-2026-85706 GitLab Path Traversal | logsource: {category: webserver} | detection: selection: cs-uri-stem|contains: '/api/v4/projects/' cs-uri-stem|contains: 'commits' cs-uri-query|re: '(%2e%2e|\.\.)[%2f%5c/\\]' sc-status|not_in: [401, 403] | condition: selection
  • Linux auditd on the GitLab host: Flag unexpected file reads by the git or gitlab-workhorse user outside /var/opt/gitlab and /home/git: -a always,exit -F arch=b64 -S openat -F uid=998 -F path!=/var/opt/gitlab -k gitlab_path_traversal
  • EDR process-ancestry alert: Alert on child processes of gitlab-workhorse or gitaly opening files under /etc/, /root/, /home/, or /proc/ — any file access outside the defined working directory tree is anomalous and warrants immediate triage.
  • Network telemetry (Zeek): Elevated volume of HTTP 200 responses to /api/v4/projects/*/repository/commits requests lacking an Authorization or PRIVATE-TOKEN header: http.uri ~ /api/v4/projects/.+/repository/commits/ && !http.request_header_names ~ /authorization/i && http.status_code == 200

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamigitlab
18.7.019.0.019.1.019.2.019.3.0

Metrics

10.0
Source: cna-v3
99.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
93.0 %
High — model estimates ≥ 50% chance of real-world exploitation within 30 days.
Published
2026-09-15 08:59 UTC
CWE-22

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Modified Analysis2026-09-24 12:52 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 18.7.0 up to (excluding) 19.1.8 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.2.0 up to (excluding) 19.2.6 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.2 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 18.7.0 up to (excluding) 19.1.8 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.2.0 up to (excluding) 19.2.6 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.2 → OR *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.2.0 up to (excluding) 19.2.6 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.2 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.2.0 up to (excluding) 19.2.6 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.2 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 18.7.0 up to (excluding) 18.11.12 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.0.0 up to (excluding) 19.0.9 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 18.7.0 up to (excluding) 18.11.12 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.0.0 up to (excluding) 19.0.9 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.1.0 up to (excluding) 19.1.8 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.1.0 up to (excluding) 19.1.8
  2. CVE Modified2026-09-23 22:16 UTC· cve@gitlab.com
    • Description: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. → GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/85xxx/CVE-2026-85706.json">CVE-2026-85706</a>
  3. Initial Analysis2026-09-14 14:22 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 18.7.0 up to (excluding) 19.1.8 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.2.0 up to (excluding) 19.2.6 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.2 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 18.7.0 up to (excluding) 19.1.8 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.2.0 up to (excluding) 19.2.6 *cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* versions from (including) 19.3.0 up to (excluding) 19.3.2
    • Reference Type: GitLab Inc.: https://gitlab.com/gitlab-org/gitlab/-/work_items/627748 Types: Broken Link
    • Reference Type: GitLab Inc.: https://hackerone.com/reports/3909881 Types: Permissions Required
    • Reference Type: CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706 Types: Third Party Advisory, US Government Resource
  4. CVE CISA KEV Update2026-09-12 13:00 UTC· 9119a7d8-5eab-497f-8521-727c672e3725
    • Date Added: 2026-09-11
    • Due Date: 2026-09-11
    • Required Action: 2026-09-11
    • Vulnerability Name: 2026-09-11
  5. CVE Modified2026-09-12 11:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706
    • SSVC: {"id":"CVE-2026-85706","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2026-85706","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…

Linked advisories